H2O vulnerable to read from uninitialized pointer in the reverse proxy handler
CVE-2023-30847

8.2HIGH

Key Information:

Vendor

H2o

Status
Vendor
CVE Published:
27 April 2023

What is CVE-2023-30847?

A vulnerability in the H2O HTTP server, prior to version 2.3.0, arises from the reverse proxy handler's mishandling of invalid HTTP requests. When attempting to construct an upstream URL, the server reads from an uninitialized pointer, potentially resulting in application crashes or unauthorized information exposure to backend HTTP servers. Users are advised to upgrade to commit f010336 or newer to mitigate this issue.

Affected Version(s)

h2o <= 2.3.0-beta2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.