CVE-2017-10908: Input Validation
Published Dec 22, 2017
·Updated
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.
Affected Software
1 affected component
Dena H2o<=2.2.3
Event History
Dec 22, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-10908?
The severity of CVE-2017-10908 is high with a CVSS score of 7.5.
2
How does CVE-2017-10908 impact H2O version 2.2.3 and earlier?
CVE-2017-10908 allows remote attackers to cause a denial of service in H2O version 2.2.3 and earlier by sending specially crafted HTTP/2 headers.
3
Which software versions are affected by CVE-2017-10908?
H2O version 2.2.3 and earlier on Microsoft Windows Server 2022 are affected by CVE-2017-10908.
4
Is there a fix for CVE-2017-10908?
Updating to a version of H2O later than 2.2.3 will fix CVE-2017-10908.
5
Where can I find more information about CVE-2017-10908?
You can find more information about CVE-2017-10908 on the GitHub issue and JVN pages.