Assigner | certcc |
Reserved | 2024-03-21 |
Published | 2024-04-03 |
Updated | 2024-06-04 |
Description
Tempesta FW rate limits are not enabled by default. They are either set too large to capture empty CONTINUATION frames attacks or too small to handle normal HTTP requests appropriately.
Problem types
CWE-1188: Initialization of a Resource with an Insecure Default
CWE-204: Inadequate Information Flow Control
Product status
References
https://github.com/tempesta-tech/tempesta/security/advisories/GHSA-3xwj-5ch3-q9p4
https://www.kb.cert.org/vuls/id/421644
http://www.openwall.com/lists/oss-security/2024/04/03/16