H2O vulnerable to read from uninitialized pointer in the reverse proxy handler
CVE-2023-30847
8.2HIGH
What is CVE-2023-30847?
A vulnerability in the H2O HTTP server, prior to version 2.3.0, arises from the reverse proxy handler's mishandling of invalid HTTP requests. When attempting to construct an upstream URL, the server reads from an uninitialized pointer, potentially resulting in application crashes or unauthorized information exposure to backend HTTP servers. Users are advised to upgrade to commit f010336 or newer to mitigate this issue.
Affected Version(s)
h2o <= 2.3.0-beta2