CVE-2024-45397

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control does not detect and prohibit HTTP requests conveyed by packets with a spoofed source address. This behavior allows attackers on the network to execute HTTP requests from addresses that are otherwise rejected by the address-based access control. The vulnerability has been addressed in commit 15ed15a. Users may disable the use of TCP FastOpen and QUIC to mitigate the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dena:h2o:*:*:*:*:*:*:*:*

History

12 Nov 2024, 20:14

Type Values Removed Values Added
References () https://github.com/h2o/h2o/commit/15ed15a2efb83a77bb4baaa5a119e639c2f6898a - () https://github.com/h2o/h2o/commit/15ed15a2efb83a77bb4baaa5a119e639c2f6898a - Patch
References () https://github.com/h2o/h2o/security/advisories/GHSA-jf2c-xjcp-wg4c - () https://github.com/h2o/h2o/security/advisories/GHSA-jf2c-xjcp-wg4c - Vendor Advisory
References () https://h2o.examp1e.net/configure/http3_directives.html - () https://h2o.examp1e.net/configure/http3_directives.html - Product
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : 7.5
CWE CWE-290
CPE cpe:2.3:a:dena:h2o:*:*:*:*:*:*:*:*
First Time Dena h2o
Dena

15 Oct 2024, 12:58

Type Values Removed Values Added
Summary
  • (es) h2o es un servidor HTTP compatible con HTTP/1.x, HTTP/2 y HTTP/3. Cuando se recibe una solicitud HTTP que utiliza datos tempranos TLS/1.3 sobre paquetes TCP Fast Open o QUIC 0-RTT y se utiliza el control de acceso basado en direcciones IP, el control de acceso no detecta ni prohíbe las solicitudes HTTP transmitidas por paquetes con una dirección de origen falsificada. Este comportamiento permite a los atacantes de la red ejecutar solicitudes HTTP desde direcciones que, de otro modo, serían rechazadas por el control de acceso basado en direcciones. La vulnerabilidad se ha abordado en el commit 15ed15a. Los usuarios pueden desactivar el uso de TCP FastOpen y QUIC para mitigar el problema.

11 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-11 15:15

Updated : 2024-11-12 20:14


NVD link : CVE-2024-45397

Mitre link : CVE-2024-45397

CVE.ORG link : CVE-2024-45397


JSON object : View

Products Affected

dena

  • h2o
CWE
CWE-290

Authentication Bypass by Spoofing

CWE-284

Improper Access Control