Denial of Service Vulnerability in H2O Web Server by H2O
CVE-2017-10868

7.5HIGH

Key Information:

Vendor

Kazuho Oku

Status
Vendor
CVE Published:
22 December 2017

What is CVE-2017-10868?

H2O Web Server versions up to and including 2.2.2 are susceptible to a denial of service attack, where attackers can exploit this vulnerability using specially crafted HTTP/1 headers to disrupt server operations. This could lead to service unavailability, impacting businesses that rely on H2O for their web hosting. Prompt updates are recommended to mitigate this risk.

Affected Version(s)

H2O version 2.2.2 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.