Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Vulnerability Description
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks.
To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
smithy-lang Smithy Rust 资源管理错误漏洞
Vulnerability Description
smithy-lang Smithy Rust是smithy-lang组织的一个Rust语言实现的模型化服务定义工具。 smithy-lang Smithy Rust 0.66.4及之前版本存在资源管理错误漏洞,该漏洞源于默认serve()路径缺少连接和标头读取超时以及并发连接限制,可能导致远程攻击者通过打开大量连接并发送从未完成的半请求,耗尽服务器套接字和任务,从而造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A