Skip to content

Denial of Service through slow HTTP responses

High
Gargron published GHSA-9pxv-6qvf-pjwc Jul 6, 2023

Package

No package listed

Affected versions

all

Patched versions

4.1.3, 4.0.5, 3.5.9

Description

(This advisory describes an issue found by Cure53 as part of an audit performed at Mozilla's request)

When performing outgoing HTTP queries, Mastodon sets a timeout on individual read operations, but a malicious server can indefinitely extend the duration of the response through slowloris-type attacks.

Impact

This vulnerability can be used to keep all Mastodon workers busy for an extended duration of time, leading to the server becoming unresponsive.

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE ID

CVE-2023-36461

Weaknesses

No CWEs

Credits