[FREEBSD:F25A34B1-910D-11EE-A1A2-641C67A117D8] varnish -- HTTP/2 Rapid Reset Attack

Severity High
Affected Packages 2
CVEs 1

Varnish Cache Project reports:

  A denial of service attack can be performed on Varnish Cache servers
that have the HTTP/2 protocol turned on. An attacker can create a large
volume of streams and immediately reset them without ever reaching the
maximum number of concurrent streams allowed for the session, causing
the Varnish server to consume unnecessary resources processing requests
for which the response will not be delivered.
Package Affected Version
pkg:freebsd/varnish7 < 7.4.2
pkg:freebsd/varnish6 < 6.6.3
ID
FREEBSD:F25A34B1-910D-11EE-A1A2-641C67A117D8
Severity
high
Severity from
CVE-2023-44487
URL
http://vuxml.freebsd.org/freebsd/f25a34b1-910d-11ee-a1a2-641c67a117d8.html
Published
2023-11-13T00:00:00
(10 months ago)
Modified
2023-12-02T00:00:00
(9 months ago)
Rights
FreeBSD VuXML Security Team
Other Advisories
Source # ID Name URL
FreeBSD VuXML https://varnish-cache.org/security/VSV00013.html
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/varnish7 varnish7 < 7.4.2
Affected pkg:freebsd/varnish6 varnish6 < 6.6.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...