https://seclists.org/oss-sec/2023/q4/144: CVE-2023-44487: HTTP/2 Rapid Reset attack against many implementations
Published Oct 18, 2023
·Updated
Affected Software
8 affected components
Apache httpd
Project Contour Contour
gRPC gRPC-Go
HAProxy HAProxy
Kazu Yamamoto http2
Kubernetes kubernetes
Linkerd Linkerd
Netty Netty
Frequently Asked Questions
1
What is the severity of CVE-2023-44487?
CVE-2023-44487 is considered a critical vulnerability that affects multiple HTTP/2 implementations.
2
How do I fix CVE-2023-44487?
To fix CVE-2023-44487, update your affected HTTP/2 implementations to the latest patched versions provided by the maintainers.
3
Which software is affected by CVE-2023-44487?
CVE-2023-44487 affects several implementations including Apache httpd, gRPC, HAProxy, and Kubernetes.
4
What is the nature of the CVE-2023-44487 vulnerability?
CVE-2023-44487 involves an HTTP/2 Rapid Reset attack that can cause disruptions in service.
5
Are there any known exploits for CVE-2023-44487?
As of now, there are no public exploits reported for CVE-2023-44487, but it is advisable to implement mitigations.