CVE-2023-4540
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Sep 5, 2023
Updated: Oct 13, 2023
CWE ID 755
Summary
CVE-2023-4540 is a vulnerability affecting the Daurnimator lua-http library. This issue arises from improper handling of exceptional conditions, allowing an attacker to execute a Denial of Service (DoS) attack through excessive allocation. By sending a specially crafted request, an attacker can cause the server to exhaust its resources and become unresponsive. This vulnerability affects all versions of lua-http before commit ddab283.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.