Denial of Service (DoS) Affecting github.com/projectcalico/calico/typha/pkg/syncserver package, versions <3.28.0-0.dev


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (40th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Denial of Service (DoS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMPROJECTCALICOCALICOTYPHAPKGSYNCSERVER-6050121
  • published13 Nov 2023
  • disclosed6 Nov 2023
  • creditrodrigorfk

Introduced: 6 Nov 2023

CVE-2023-41378  (opens in a new tab)
CWE-400  (opens in a new tab)

How to fix?

Upgrade github.com/projectcalico/calico/typha/pkg/syncserver to version 3.28.0-0.dev or higher.

Overview

github.com/projectcalico/calico/typha/pkg/syncserver is an open source system enabling cloud native application connectivity and policy. Calico integrates with major orchestration systems like Kubernetes, Apache Mesos, Docker, OpenStack and more to provide a seamless experience for developers and operators.

Calico is a Tigera open source project, and is primarily maintained by the Tigera team.

Affected versions of this package are vulnerable to Denial of Service (DoS) during TLS handshake calls. This handshake can block the main server loop indefinitely, leaving other connections idle as they wait for the handshake to finish.

CVSS Base Scores

version 3.1