In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessive resource usage during proxy operations via crafted requests, potentially leading to a denial of service with relatively few incoming requests. This vulnerability only exists in the OpenResty fork in the openresty/luajit2 GitHub repository. The LuaJIT/LuaJIT repository. is unaffected.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-407 | |
Metrics |
cvssV3_1
|
ssvc
|
Wed, 11 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-400 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-23T00:00:00
Updated: 2024-11-26T17:58:14.207Z
Reserved: 2024-06-27T00:00:00
Link: CVE-2024-39702
Vulnrichment
Updated: 2024-08-02T04:26:16.211Z
NVD
Status : Awaiting Analysis
Published: 2024-07-23T16:15:05.557
Modified: 2024-11-26T18:15:19.193
Link: CVE-2024-39702
Redhat