CVE-2024-34079
CVSS V2 None
CVSS V3 None
Description
octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0
Overview
- CVE ID
- CVE-2024-34079
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-05-10T19:05:49.063Z
- Last Modified Date
- 2024-06-04T17:41:26.463Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/octo-sts/app/security/advisories/GHSA-75r6-6jg8-pfcq | x_refsource_CONFIRM |
https://github.com/octo-sts/app/commit/74ba874c017cf973edd6711144cf4399a9fcff57 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-34079 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34079 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 14:24:57 | Added to TrackCVE |