Уязвимость распределения ресурсов без ограничений или регулирования в DivvyPayHQ absinthe_federation позволяет неаутентифицированному удаленному злоумышленнику прервать работу виртуальной машины Erlang с помощью созданных ключей представления _entities. Каждый ключ каждого объекта в аргументе представлений поля _entities, установленного федерацией, преобразуется с помощью String.to_atom/1 с помощью Convert_key/2 в lib/absinthe/federation/schema/entities_field.ex. Представления типизированы как открытый скаляр _Any, поэтому его ключи обходят приведение схемы, и злоумышленник свободно называет их.
Атомы никогда не подвергаются сборке мусора, а таблица атомов BEAM жестко ограничена (около 1 048 576 записей по умолчанию), поэтому один запрос, несущий десятки тысяч уникальных ключей, создает такое количество постоянных атомов, а несколько таких запросов исчерпывают таблицу и прерывают работу узла. Влияние ограничивается доступностью: данные не считываются и не изменяются, а для восстановления требуется перезапуск приложения. Эта проблема затрагивает absinthe_federation: с 0.1.0 до 0.9.3.
Показать оригинальное описание (EN)
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys. Every key of every object in the representations argument of the federation-mandated _entities field is converted with String.to_atom/1 by convert_key/2 in lib/absinthe/federation/schema/entities_field.ex. representations is typed as the open-ended _Any scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node. The impact is confined to availability: no data is read or altered, and recovery requires restarting the application. This issue affects absinthe_federation: from 0.1.0 before 0.9.3.
Характеристики атаки
Последствия
Строка CVSS v4.0
Тип уязвимости (CWE)
Уязвимые продукты 1
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Divvypayhq Absinthe_Federation
cpe:2.3:a:divvypayhq:absinthe_federation:*:*:*:*:*:*:*:*
|
0.1.0
|
0.9.3
|