Skip to content

Commit

Permalink
security/vuxml: add h2o-devel vuln details
Browse files Browse the repository at this point in the history
Security:	CVE-2023-44487
Sponsored by:	SkunkWerks, GmbH
  • Loading branch information
dch committed Oct 10, 2023
1 parent cf4cc1d commit e247a75
Showing 1 changed file with 35 additions and 0 deletions.
35 changes: 35 additions & 0 deletions security/vuxml/vuln/2023.xml
Original file line number Diff line number Diff line change
@@ -1,3 +1,38 @@
<vuln vid="bf545001-b96d-42e4-9d2e-60fdee204a43">
<topic>h2o -- HTTP/2 Rapid Reset attack vulnerability</topic>
<affects>
<package>
<name>h2o</name>
<range><le>2.2.6</le></range>
</package>
<package>
<name>h2o-devel</name>
<range><lt>2.3.0.d.20231010</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>Kazuo Okuhu reports:</p>
<blockquote cite="https://github.com/h2o/h2o/issues/3291">
<p>
H2O is vulnerable to the HTTP/2 Rapid Reset attack.
An attacker might be able to consume more than adequate amount of
processing power of h2o and the backend servers by mounting the
attack.
</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2023-44487</cvename>
<url>https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf</url>
</references>
<dates>
<discovery>2023-10-10</discovery>
<entry>2023-10-10</entry>
</dates>
</vuln>

<vuln vid="4f254817-6318-11ee-b2ff-080027de9982">
<topic>Django -- multiple vulnerabilities</topic>
<affects>
Expand Down

0 comments on commit e247a75

Please sign in to comment.