Loading HuntDB...

Slowvote and Countdown can cause Denial of Service due to recursive inclusion

P
Phabricator
Submitted None
Reported by dyls

Vulnerability Details

Technical details and impact analysis

Uncontrolled Resource Consumption
Similar to #85011, if you edit a Slowvote or Countdown object and include its own object ID in the description, then it will recursively include and prevent the page from loading. mongoose ## Impact Denial of Service. You can include the Slowvote or Countdown object on any other object to also prevent it from loading. If it is included in the feed, you could also prevent the home page from loading.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Uncontrolled Resource Consumption