Denial of Service in apostrophe
Low severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Jan 9, 2023
Versions of
apostrophe
prior to 2.97.1 are vulnerable to Denial of Service. Theapostrophe-jobs
module sets a callback for incoming jobs and doesn't clear it regardless of its status. This causes the server to accumulate callbacks, allowing an attacker to start a large number of jobs and exhaust system memory.Recommendation
Upgrade to version 2.97.1 or later.
References