The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerabilities in an interactive lesson.
Start learningThere is no fixed version for github.com/ethereum/go-ethereum
.
github.com/ethereum/go-ethereum is an Official Golang implementation of the Ethereum protocol.
Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') when the --http --graphql
options are used, an attacker can cause a denial of service by consuming excessive memory and causing the daemon to hang by sending a specially crafted GraphQL query.
Note
The vendor's position is that the GraphQL
endpoint is not designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic.