CVE-2024-45403
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 11, 2024
Updated: Nov 12, 2024
CWE ID 617
Summary
CVE-2024-45403 is a vulnerability affecting the h2o HTTP server, which supports HTTP/1.x, HTTP/2, and HTTP/3. When acting as a reverse proxy and an HTTP/3 request is cancelled by the client, h2o may crash due to an assertion failure. An attacker can exploit this crash to launch a Denial-of-Service (DoS) attack. By default, h2o restarts after a crash, but ongoing HTTP requests will be disrupted. Users can mitigate the issue by disabling HTTP/3 support. The vulnerability has been resolved in commit 1ed32b2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.