https://seclists.org/oss-sec/2023/q4/95: CVE-2023-44487: HTTP/2 Rapid Reset attack against many implementations
Published Oct 13, 2023
·Updated
Affected Software
2 affected components
Apache Trafficserver
Lighttpd Lighttpd
Frequently Asked Questions
1
What is the severity of CVE-2023-44487?
CVE-2023-44487 is considered a high severity vulnerability that affects multiple HTTP/2 implementations.
2
How do I fix CVE-2023-44487?
To fix CVE-2023-44487, ensure your HTTP/2 implementation is updated to the latest version or apply any available patches from the respective vendors.
3
What systems are affected by CVE-2023-44487?
CVE-2023-44487 affects several HTTP/2 implementations, including Apache Trafficserver and Lighttpd.
4
What type of attack does CVE-2023-44487 facilitate?
CVE-2023-44487 enables a Rapid Reset attack that can disrupt service by overwhelming the server.
5
When was CVE-2023-44487 published?
CVE-2023-44487 was published on October 13, 2023.