Lucene search

K
githubGitHub Advisory DatabaseGHSA-7F4J-64P6-5H5V
HistoryApr 15, 2024 - 6:14 p.m.

Traefik affected by HTTP/2 CONTINUATION flood in net/http

2024-04-1518:14:51
GitHub Advisory Database
github.com
15
traefik
vulnerability
http/2
continuation
flood
net/http
patch
advisory
issue
software

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

13.2%

There is a potential vulnerability in Traefik managing HTTP/2 connections.

More details in the CVE-2023-45288.

Patches

Workarounds

No workaround

For more information

If you have any questions or comments about this advisory, please open an issue.

Affected configurations

Vulners
Node
traefiktraefikRange3.0.0-rc13.0.0-rc5
OR
traefiktraefikRange<2.11.2
VendorProductVersionCPE
traefiktraefik*cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

13.2%