Description
octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/octo-sts/app/security/advisories/GHSA-75r6-6jg8-pfcq
Patch x_refsource_misc
https://github.com/octo-sts/app/commit/74ba874c017cf973edd6711144cf4399a9fcff57
Scores
CVSS v3
3.7
EPSS
0.0006
EPSS Percentile
17.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (2)
octo-sts/app
0 - 0.1.0Go
octo-sts/app
< 0.1.0
Published
May 14, 2024
Tracked Since
Feb 18, 2026