CVE-2024-45397
HIGH EPSS 35.0%
Published Oct 11, 20241y ago · Modified Jun 17, 20261w ago
7.5 CVSS 3.1
Published Oct 11, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control does not detect and prohibit HTTP requests conveyed by packets with a spoofed source address. This behavior allows attackers on the network to execute HTTP requests from addresses that are otherwise rejected by the address-based access control. The vulnerability has been addressed in commit 15ed15a. Users may disable the use of TCP FastOpen and QUIC to mitigate the issue.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
35.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 2
CWE-284
CWE-290
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| dena | h2o | * | <2024-10-10 |
References 3
- github.com https://github.com/h2o/h2o/commit/15ed15a2efb83a77bb4baaa5a119e639c2f6898a
- github.com https://github.com/h2o/h2o/security/advisories/GHSA-jf2c-xjcp-wg4c
- h2o.examp1e.net https://h2o.examp1e.net/configure/http3_directives.html
Remediation
- github.com https://github.com/h2o/h2o/commit/15ed15a2efb83a77bb4baaa5a119e639c2f6898a