LOW 3.7 Go
octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
GHSA-75r6-6jg8-pfcq · CVE-2024-34079 · GO-2024-2833
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service.
Patches
This vulnerability existed in the repository at HEAD, we will cut a 0.1.0 release with the fix.
Workarounds
None
References
None
Ready to move
Start Securing
Free, no credit card | First findings in minutes