{"id":598665,"date":"2023-01-18T06:50:03","date_gmt":"2023-01-18T12:50:03","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/01\/18\/denial-of-service-vulnerability-discovered-in-libraries-used-by-github-and-others\/"},"modified":"2023-01-18T06:50:03","modified_gmt":"2023-01-18T12:50:03","slug":"denial-of-service-vulnerability-discovered-in-libraries-used-by-github-and-others","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/01\/18\/denial-of-service-vulnerability-discovered-in-libraries-used-by-github-and-others\/","title":{"rendered":"Denial of service vulnerability discovered in libraries used by GitHub and others"},"content":{"rendered":"<div id=\"boilerplate_2682874\">\n<p><em>Check out all the on-demand sessions from the Intelligent Security Summit <a href=\"https:\/\/avolio.swapcard.com\/intelligentsecuritysummit2022\/registrations\/Start?utm_source=vb&#038;utm_medium=boiler&#038;utm_content=ondemand&#038;utm_campaign=IS22_BoilerPlates\" data-type=\"URL\" data-id=\"https:\/\/avolio.swapcard.com\/intelligentsecuritysummit2022\/registrations\/Start?utm_source=vb&#038;utm_medium=boiler&#038;utm_content=ondemand&#038;utm_campaign=IS22_BoilerPlates\">here<\/a><\/em>.<\/p>\n<hr>\n<\/div>\n<p>Unlike breaches targeting sensitive data or ransomware attacks, denial of service (DoS) exploits aim to take down services and make them wholly inaccessible.\u00a0<\/p>\n<p>Several such attacks have occurred in recent memory; last June, for instance, Google <a href=\"https:\/\/cloud.google.com\/blog\/products\/identity-security\/how-google-cloud-blocked-largest-layer-7-ddos-attack-at-46-million-rps\" target=\"_blank\" rel=\"noreferrer noopener\">blocked<\/a> what at that point was the largest <a href=\"https:\/\/venturebeat.com\/security\/report-62-of-retailers-cybersecurity-incidents-come-from-automated-threats\/\">distributed denial of service (DDoS)<\/a> attack in history. <a href=\"https:\/\/www.akamai.com\/blog\/security\/record-breaking-ddos-attack-in-europe\" target=\"_blank\" rel=\"noreferrer noopener\">Akami<\/a> then broke that record in September when it detected and mitigated an assault in Europe.\u00a0<\/p>\n<p>In a recent development, <a href=\"https:\/\/www.legitsecurity.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Legit Security<\/a> today announced its discovery of an easy-to-exploit DoS vulnerability in markdown libraries used by GitHub, GitLab and other applications, using a popular markdown rendering service called commonmarker.<\/p>\n<p>\u201cImagine taking down GitHub for some time,\u201d said Liav Caspi, cofounder and CTO of the <a href=\"https:\/\/venturebeat.com\/security\/the-software-supply-chain-new-threats-call-for-new-security-measures\/\">software supply chain security<\/a> platform. \u201cThis could be a major global disruption and shut down most software development shops. The impact would likely be unprecedented.\u201d<\/p>\n<div><body><\/p>\n<div id=\"boilerplate_2803147\">\n<h3>Event<\/h3>\n<div>\n<p><span>Intelligent Security Summit On-Demand<\/span><\/p>\n<p><span>Learn the critical role of AI &#038; ML in cybersecurity and industry specific case studies. Watch on-demand sessions today.<\/span><\/p>\n<\/div>\n<p><a href=\"https:\/\/avolio.swapcard.com\/intelligentsecuritysummit2022\/registrations\/Start?utm_source=vb&#038;utm_medium=incontent&#038;utm_content=ondemand&#038;utm_campaign=IS22_InContent\"><br \/>\n                Watch Here            <\/a>\n                        <\/p>\n<\/div>\n<p><\/body><\/p>\n<p>GitHub, which did not respond to requests for comment by VentureBeat, has posted a formal acknowledgement and <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-39209\" target=\"_blank\" rel=\"noreferrer noopener\">fix<\/a>.\u00a0<\/p>\n<h2 id=\"h-denial-of-service-aim-disruption\">Denial of service aim: Disruption<\/h2>\n<p>Both <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/tips\/ST04-015\" target=\"_blank\" rel=\"noreferrer noopener\">DoS<\/a> and DDoS overload a server or web app with an aim to interrupt services.\u00a0<\/p>\n<p>As <a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/dos-vs-ddos\" target=\"_blank\" rel=\"noreferrer noopener\">Fortinet<\/a> describes it, DoS does this by flooding a server with traffic and making a website or resource unavailable; DDoS uses multiple computers or machines to flood a targeted resource.<\/p>\n<p>And, there\u2019s no question that they are on the rise \u2014 steeply, in fact. <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/solutions\/collateral\/executive-perspectives\/annual-internet-report\/white-paper-c11-741490.html\" target=\"_blank\" rel=\"noreferrer noopener\">Cisco noted<\/a> a 776% year-over-year growth in attacks of 100 to 400 gigabits per second between 2018 and 2019. The company estimates that the total number of DDoS attacks will double from 7.9 million in 2018 to 15.4 million this year.\u00a0<\/p>\n<p>But although DDoS attacks aren\u2019t always intended to score sensitive data or hefty ransom payouts, they nonetheless are costly. Per <a href=\"https:\/\/blogs.gartner.com\/andrew-lerner\/2014\/07\/16\/the-cost-of-downtime\/\" target=\"_blank\" rel=\"noreferrer noopener\">Gartner<\/a> research, the average cost of IT downtime is $5,600 per minute. Depending on organization size, the cost of downtime can range from $140,000 to as much as $5 million per hour.<\/p>\n<p>And, with so many apps incorporating open-source code \u2014 a whopping 97% by <a href=\"https:\/\/www.synopsys.com\/software-integrity\/resources\/analyst-reports\/open-source-security-risk-analysis.html?intcmp=sig-blog-ossra22\" target=\"_blank\" rel=\"noreferrer noopener\">one estimate<\/a> \u2014 organizations don\u2019t have full visibility of their security posture and potential gaps and vulnerabilities.\u00a0<\/p>\n<p>Indeed, open-source libraries are \u201cubiquitous\u201d in modern software development, said Caspi \u2014 so when vulnerabilities emerge, they can be very difficult to track due to uncontrolled copies of the original vulnerable code. When a library becomes popular and widespread, a vulnerability could potentially enable an attack on countless projects.\u00a0<\/p>\n<p>\u201cThose attacks can include disruption of critical business services,\u201d said Caspi, \u201csuch as crippling the software supply chain and the ability to release new business applications.\u201d<\/p>\n<h2 id=\"h-vulnerability-uncovered\">Vulnerability uncovered<\/h2>\n<p>As Caspi explained, markdown refers to creating formatted text using a plain text editor commonly found in software development tools and environments. A wide range of applications and projects implement these popular open-source markdown libraries, such as the popular variant found in\u00a0GitHub\u2019s implementation called\u00a0GitHub Flavored Markdown (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Markdown#GitHub_Flavored_Markdown\" target=\"_blank\" rel=\"noreferrer noopener\">GFM<\/a>). <\/p>\n<p>A copy of the vulnerable GFM implementation was found in <a href=\"https:\/\/rubygems.org\/gems\/commonmarker\" target=\"_blank\" rel=\"noreferrer noopener\">commonmarker<\/a>, the popular Ruby package implementing markdown support. (This has more than 1 million <a href=\"https:\/\/github.com\/gjtorikian\/commonmarker\/network\/dependents\" target=\"_blank\" rel=\"noreferrer noopener\">dependent repositories<\/a>.) Coined \u201cMarkDownTime,\u201d this allows an attacker to deploy a simple DoS attack that would shut down digital business services by disrupting application development pipelines, said Caspi.\u00a0<\/p>\n<p>Legit Security researchers found that it was simple to trigger unbounded resource exhaustion leading to a DoS attack. Any product that can read and display markdown (*.md files) and uses a vulnerable library can be targeted, he explained.<\/p>\n<p>\u201cIn some cases, an attacker can continuously utilize this vulnerability to keep the service down until it is entirely blocked,\u201d said Caspi.\u00a0<\/p>\n<p>He explained that Legit Security\u2019s research team was looking into vulnerabilities in GitHub and GitLab as part of its ongoing software supply chain security research. They have disclosed the security issue to the commonmarker maintainer, as well as to both GitHub and GitLab.\u00a0<\/p>\n<p>\u201cAll of them have fixed the issues, but many more copies of this markdown implementation have been deployed and are in use,\u201d said Caspi.\u00a0<\/p>\n<p>As such, \u201cprecaution and mitigation measures should be employed.\u201d<\/p>\n<h2 id=\"h-strong-controls-visibility\">Strong controls, visibility<\/h2>\n<p>To protect themselves against this vulnerability, organizations should upgrade to a safer version of the markdown library and upgrade any vulnerable product like GitLab to the newest version, Caspi advised.\u00a0<\/p>\n<p>And, generally speaking, when it comes to guarding against software supply chain attacks, organizations should have better security controls over the third-party software libraries they use. Protection also involves continuously checking for known vulnerabilities, then upgrading to safer versions.\u00a0<\/p>\n<p>Also, the reputation and popularity of open-source software should be considered \u2014 in particular, avoid unmaintained or low-reputable software. And, always keep SDLC systems like GitLab up to date and securely configured, said Caspi. <\/p>\n<p><strong>VentureBeat&#8217;s mission<\/strong> is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. <a href=\"https:\/\/info.venturebeat.com\/website-preference-center.html?utm_source=VBsite&#038;utm_medium=bottomBoilerplate\" data-type=\"URL\" data-id=\"https:\/\/info.venturebeat.com\/website-preference-center.html\">Discover our Briefings.<\/a><\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/venturebeat.com\/security\/denial-of-service-vulnerability-discovered-in-libraries-used-by-github-and-others\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Taryn Plumb<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Check out all the on-demand sessions from the Intelligent Security Summit here. Unlike breaches targeting sensitive data or ransomware attacks, denial of service (DoS) exploits aim to take down services and make them wholly inaccessible.\u00a0Several such attacks have occurred in recent memory; last June, for instance, Google blocked what at that point was the largest<\/p>\n","protected":false},"author":1,"featured_media":598666,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34501,22,46],"tags":[],"class_list":["post-598665","post","type-post","status-publish","format-standard","has-post-thumbnail","category-denial","category-service","category-technology"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/598665","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=598665"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/598665\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/598666"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=598665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=598665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=598665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}