Denial of Service Vulnerability in H2O Web Server by PayPal
CVE-2017-10908

7.5HIGH

Key Information:

Vendor

Kazuho Oku

Status
Vendor
CVE Published:
22 December 2017

What is CVE-2017-10908?

A vulnerability in the H2O web server versions 2.2.3 and earlier allows remote attackers to disrupt server operations by sending specially crafted HTTP/2 headers. This can lead to a denial of service, leaving the server unable to respond to legitimate traffic. It is crucial for administrators using affected versions to implement available patches and configure their servers accordingly to mitigate this threat.

Affected Version(s)

H2O version 2.2.3 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.