Queen of Denial of Service II
An attacker can amplify a denial of service attack through this component with amplification on the order of 10:1.
Threat |
|
You have a search feature that allows multiple search terms at the same time. For each search term, a separate search is performed internally. An attacker has cleverly crafted several search terms that will take a long time to process and has then launched multiple searches at the same time. |
|
CAPEC |
CAPEC-130 – Excessive allocation CAPEC-490 – Amplification |
ASVS |
13.4.1 – Ensure checks are performed to protect against exponential or uncontrolled |
CWE |
CWE-674 – Uncontrolled recursion CWE-776 – Improper restriction of... |