Lucene search

K
freebsdFreeBSDBF545001-B96D-42E4-9D2E-60FDEE204A43
HistoryOct 10, 2023 - 12:00 a.m.

h2o -- HTTP/2 Rapid Reset attack vulnerability

2023-10-1000:00:00
vuxml.freebsd.org
50
h2o
http/2
rapid reset
attack
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.816

Percentile

98.4%

Kazuo Okuhu reports:

	H2O is vulnerable to the HTTP/2 Rapid Reset attack.
	An attacker might be able to consume more than adequate amount of
	processing power of h2o and the backend servers by mounting the
	attack.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchh2o<= 2.2.6UNKNOWN
FreeBSDanynoarchh2o-devel< 2.3.0.d.20231010UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.816

Percentile

98.4%