Lucene search

K
redhatcveRedhat.comRH:CVE-2018-14645
HistoryJan 13, 2022 - 6:33 a.m.

CVE-2018-14645

2022-01-1306:33:57
redhat.com
access.redhat.com
16

0.003 Low

EPSS

Percentile

65.7%

A flaw was discovered in the HPACK decoder of haproxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

Mitigation

HTTP/2 support is disabled by default on OpenShift Container Platform 3.11. To mitigate this vulnerability keep it disabled. You can verify if HTTP/2 support is enabled by following the instructions in the upstream pull request, [1].

[1] <https://github.com/openshift/origin/pull/19968&gt;