github.com/cyberark/secretless-broker is vulnerable to Uncontrolled Resource Consumption
20
Low Risk
Affected versions of this package do not enforce message length limits in the PostgreSQL protocol handler, allowing excessively large startup or authentication messages that can trigger uncontrolled memory allocation and lead to denial-of-service conditions. An attacker could exploit this by sending specially crafted oversized packets to the server, exhausting memory resources and causing performance degradation or service unavailability.
You are affected if you are using a version that falls within the vulnerable range.
github.com/cyberark/secretless-broker is vulnerable to Uncontrolled Resource Consumption in versions 1.0.0 - 1.7.31.
Upgrade the github.com/cyberark/secretless-broker library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant