QID 996489
Date Published: 2024-01-04
QID 996489: GO (Go) Security Update for github.com/cubefs/cubefs (GHSA-qc6v-g3xw-grmx)
A security vulnerability was found in CubeFS HandlerNode that could allow authenticated users to send maliciously-crafted requests that would crash the ObjectNode and deny other users from using it. The root cause was improper handling of incoming HTTP requests that could allow an attacker to control the ammount of memory that the ObjectNode would allocate. A malicious request could make the ObjectNode allocate more memory that the machine had available, and the attacker could exhaust memory by way of a single malicious request.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qc6v-g3xw-grmx for updates and patch information.
Vendor References
- GHSA-qc6v-g3xw-grmx -
github.com/advisories/GHSA-qc6v-g3xw-grmx
CVEs related to QID 996489
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qc6v-g3xw-grmx | github.com/cubefs/cubefs |
|