Denial of Service Vulnerability in H2O Web Server by H2O
CVE-2017-10872

6.5MEDIUM

Key Information:

Vendor

Kazuho Oku

Status
Vendor
CVE Published:
22 December 2017

What is CVE-2017-10872?

The H2O web server versions up to 2.2.3 are susceptible to a denial of service attack, allowing remote attackers to disrupt server operations. This vulnerability can be exploited through unspecified vectors, which may lead to service interruptions and unavailability, affecting users and applications relying on the web server for operational functionality.

Affected Version(s)

H2O version 2.2.3 and earlier

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.