The eventing-github cluster-local server doesn't set ReadHeaderTimeout
which could lead do a DDoS attack, where a large group of users send requests to the server causing the server to hang for long enough to deny it from being available to other users, also know as a Slowloris attack.
Fix in v1.12.1
and v1.11.3
The vulnerability was reported by Ada Logics during an ongoing security audit of Knative involving Ada Logics, the Knative maintainers, OSTIF and CNCF.
{ "nvd_published_at": null, "cwe_ids": [ "CWE-400" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-12-06T19:19:35Z" }