https://seclists.org/oss-sec/2023/q4/75: CVE-2023-44487: HTTP/2 Rapid Reset attack against many implementations
Published Oct 10, 2023
·Updated
Affected Software
14 affected components
Apache httpd
Caddy Caddy
Envoy Envoy
go golang
h2o h2o
HAProxy HAProxy
Jetty jetty>=9.4.53.v20231009<=12.0.2
Netty Netty
nghttp2 nghttp2
Nginx nginx
Node.js Node.js
Facebook Proxygen
SWIFT NIO HTTP/2
Apache Tomcat>=8.5.94<11.0.0-M12
Frequently Asked Questions
1
What is the severity of CVE-2023-44487?
CVE-2023-44487 is considered a high severity vulnerability due to its potential for denial-of-service attacks.
2
How do I fix CVE-2023-44487?
To fix CVE-2023-44487, upgrade your HTTP/2 implementation to the latest version provided by your software vendor.
3
Which software is affected by CVE-2023-44487?
CVE-2023-44487 affects multiple implementations including Apache httpd, Caddy, Envoy, Go, h2o, HAProxy, and Jetty.
4
What type of attack does CVE-2023-44487 facilitate?
CVE-2023-44487 facilitates a denial-of-service attack through the HTTP/2 Rapid Reset mechanism.
5
When was CVE-2023-44487 published?
CVE-2023-44487 was published on October 10, 2023.