LOW 3.7 Go

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

GHSA-75r6-6jg8-pfcq · CVE-2024-34079 · GO-2024-2833

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service.

Patches

This vulnerability existed in the repository at HEAD, we will cut a 0.1.0 release with the fix.

Workarounds

None

References

None

Ready to move

Start Securing

Free, no credit card | First findings in minutes