CVE-2020-28349: Improper Input Validation
(updated )
** DISPUTED ** An inaccurate frame deduplication process in ChirpStack Network Server allows a malicious gateway to perform uplink Denial of Service via malformed frequency attributes in CollectAndCallOnceCollect
in internal/uplink/collect.go.
NOTE: The vendor’s position is that there are no “guarantees that allowing untrusted LoRa gateways to the network should still result in a secure network.”
References
Detect and mitigate CVE-2020-28349 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →