CVE-2023-37279
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Sep 20, 2023
Updated: Sep 25, 2023
CWE ID 789
CWE ID 770
Summary
CVE-2023-37279 is a denial-of-service vulnerability affecting Faktory, a language-agnostic persistent background job server, prior to version 1.8.0. Malicious URL query parameters with a large value for the `days` parameter can cause the Faktory web dashboard to read an excessive amount of memory, leading to a server crash. The issue arises due to the backend's lack of validation on the `days` parameter value. The vulnerability has been resolved in version 1.8.0 with the necessary checks and improvements to prevent such memory-consuming queries.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share