QID 980109
QID 980109: Go (go) Security Update for github.com/cloudflare/cfrpki/cmd/octorpki (GHSA-8cvr-4rrf-f244)
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.
## Patches
## For more information
If you have any questions or comments about this advisory email us at [email protected]
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8cvr-4rrf-f244 for updates pertaining to this vulnerability.
Vendor References
- GHSA-8cvr-4rrf-f244 -
github.com/advisories/GHSA-8cvr-4rrf-f244
CVEs related to QID 980109
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8cvr-4rrf-f244 | github.com/cloudflare/cfrpki/cmd/octorpki |
|