Uploaded image for project: 'Apache YuniKorn'
  1. Apache YuniKorn
  2. YUNIKORN-2182

Set ReadHeaderTimeout in http server

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • core - common, webapp

    Description

      Potential Slowloris Attack because ReadHeaderTimeout is not configured in the http.Server (gosec)

      We do not set ReadTimeout or ReadHeaderTimeout so we do not have a timeout at all at the moment.

      BTW: this is not important for the webtest servers we build as they are just for our tests.

      Attachments

        Activity

          People

            KatLantyss Chen, Kai-Chun
            wilfreds Wilfred Spiegelenburg
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: