漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Vulnerability Description
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks.
To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
smithy-lang Smithy Rust 资源管理错误漏洞
Vulnerability Description
smithy-lang Smithy Rust是smithy-lang组织的一个Rust语言实现的模型化服务定义工具。 smithy-lang Smithy Rust 0.66.4及之前版本存在资源管理错误漏洞,该漏洞源于默认serve()路径缺少连接和标头读取超时以及并发连接限制,可能导致远程攻击者通过打开大量连接并发送从未完成的半请求,耗尽服务器套接字和任务,从而造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A