Queen of Denial of Service I
An attacker can amplify a denial of service attack through this component with amplification on the order of 10:1.
Threat |
|
A part of your system doesn’t restrict the size of the data it can process, and you also have an endpoint that allows you to perform batch processing with this already vulnerable part of the system. |
|
CAPEC |
CAPEC-572 – Artificially inflate file sizes CAPEC-231 – Oversized serialized data payloads |
ASVS |
12.1.1 – Ensure files won’t fill your disk 12.1.2 – Ensure extracted archives won’t fill your disk |
CWE |
CWE-770 – Allocation of resources without limits or throttling |