Headline
GHSA-xhw9-4wqq-x67v: rdiffweb vulnerable to potential DoS via memory consumption
rdiffweb prior to 2.4.8 is vulnerable to a potential Dos attack via an unlimited length “title” field when adding an SSH key. This can result in excess memory consumption, leading to a Denial of Service (DoS). This issue is patched in version 2.4.8. There are no known workarounds.
rdiffweb vulnerable to potential DoS via memory consumption
High severity GitHub Reviewed Published Sep 27, 2022 • Updated Sep 30, 2022
Related news
CVE-2022-3298
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.