Uploaded image for project: 'Shindig'
  1. Shindig
  2. SHINDIG-1834

DOS vulnerability with closure compiler in feature js endpoint

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 2.5.0-beta1, 2.5.0-beta2
    • 2.5.0-beta3
    • Java, Javascript
    • None

    Description

      Varying features and options on the request made to this endpoint will cause closure to run each time a cached version is not found. This can effectively DOS the server, as closure is pretty expensive and the permutations of feature combinations are practically endless.

      Attachments

        Activity

          People

            ddumont Dan Dumont
            ddumont Dan Dumont
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: