Resource exhaustion in CF Deployment and Routing Release - CVE-2020-5416
Published: September 1, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources, when used in a deployment with NGINX reverse proxies in front of the Gorouters. A remote attacker can send specially crafted HTTP requests, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Routing Release
How to mitigate CVE-2020-5416
Routing Release - update to 0.204.0