THREAT OPS › Threat News › [GHSA] GHSA-5x78-73v4-xg6w (high) — postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
[GHSA] GHSA-5x78-73v4-xg6w (high) — postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
GHSA-5x78-73v4-xg6w Severity: high CVE: None
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
A malicious, compromised, or man-in-the-middle server can supply an arbitrarily large SCRAM-SHA-256 PBKDF2 iteration count during authentication. The client runs it inline with no upper bound, pinning a `tokio` worker thread for minut
Original source: https://github.com/advisories/GHSA-5x78-73v4-xg6w