Description
Tempesta FW rate limits are not enabled by default. They are either set too large to capture empty CONTINUATION frames attacks or too small to handle normal HTTP requests appropriately.
Problem types
CWE-1188: Initialization of a Resource with an Insecure Default
CWE-204: Inadequate Information Flow Control
Product status
References
github.com/...mpesta/security/advisories/GHSA-3xwj-5ch3-q9p4
www.kb.cert.org/vuls/id/421644
www.openwall.com/lists/oss-security/2024/04/03/16