HTTP Request Spoofing Vulnerability in h2o HTTP Server
CVE-2024-45397
What is CVE-2024-45397?
The H2O HTTP server implements an exposure through its handling of HTTP requests utilizing TLS/1.3 early data when combined with TCP Fast Open or QUIC 0-RTT packets. A significant security flaw arises when IP address-based access controls are configured, as the system fails to identify and deny HTTP requests sent from spoofed source addresses. This vulnerability poses a risk, allowing attackers to launch HTTP requests from addresses that would typically be blocked by the configuration. To mitigate the issue, users are advised to disable the use of TCP Fast Open and QUIC. The vulnerability has been addressed in commit 15ed15a.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
h2o < 15ed15a2efb83a77bb4baaa5a119e639c2f6898a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
