CVE-2023-43622
Apache HTTP Server: DoS in HTTP/2 with initial windows size 0
7.5
HIGH
CVSS 3.1
EPSS 70.6%
描述
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57. Users are recommended to upgrade to version 2.4.58, which fixes the issue.
如何修補 CVE-2023-43622
要修補 CVE-2023-43622,請將受影響套件升級到下列已修補版本。
- —升級至 2.4.58-r0 或更新版本
- —升級至 2.4.58 或更新版本
- —升級至 2.4.59-1~deb11u1 或更新版本
CVE-2023-43622 正在被利用嗎?
可能 — EPSS 為 70.6%,屬於高被利用機率區間,建議優先修補。
受影響套件(3)
- from 0, < 2.4.58-r0
- >= 2.4.55, < 2.4.58
- from 0, < 2.4.59-1~deb11u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |