Slowvote and Countdown can cause Denial of Service due to recursive inclusion
P
Phabricator
Submitted None
Actions:
Reported by
dyls
Vulnerability Details
Technical details and impact analysis
Similar to #85011, if you edit a Slowvote or Countdown object and include its own object ID in the description, then it will recursively include and prevent the page from loading.
mongoose
## Impact
Denial of Service. You can include the Slowvote or Countdown object on any other object to also prevent it from loading. If it is included in the feed, you could also prevent the home page from loading.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Uncontrolled Resource Consumption