h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control does not detect and prohibit HTTP requests conveyed by packets with a spoofed source address. This behavior allows attackers on the network to execute HTTP requests from addresses that are otherwise rejected by the address-based access control. The vulnerability has been addressed in commit 15ed15a. Users may disable the use of TCP FastOpen and QUIC to mitigate the issue.
References
Configurations
History
12 Nov 2024, 20:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/h2o/h2o/commit/15ed15a2efb83a77bb4baaa5a119e639c2f6898a - Patch | |
References | () https://github.com/h2o/h2o/security/advisories/GHSA-jf2c-xjcp-wg4c - Vendor Advisory | |
References | () https://h2o.examp1e.net/configure/http3_directives.html - Product | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-290 | |
CPE | cpe:2.3:a:dena:h2o:*:*:*:*:*:*:*:* | |
First Time |
Dena h2o
Dena |
15 Oct 2024, 12:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Oct 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-11 15:15
Updated : 2024-11-12 20:14
NVD link : CVE-2024-45397
Mitre link : CVE-2024-45397
CVE.ORG link : CVE-2024-45397
JSON object : View
Products Affected
dena
- h2o