bbangert / beaker

WSGI middleware for sessions and caching
https://beaker.readthedocs.org/
Other
517 stars 147 forks source link

Resource consumption dos from way back #216

Open grampae opened 3 years ago

grampae commented 3 years ago

Going way back to 2019 I had submitted a vulnerability to Ubiquiti Edgemax devices, it was a denial of service by filling up the beaker.session.id stored locally on the device until it had a resource consumption issue.

It just thought about it again for whatever reason and maybe I should have submitted something to the source. I am imagining it was just a problem because the device had limited space.

That being said has this been an issue for any other devices using beaker with limited resources or has this been patched in the past.

Thanks for humoring me.

Here is a link to the proof of concept i created to test for this problem.

https://github.com/grampae/meep