Resource exhaustion in Apache Traffic Server - CVE-2024-31309
Published: April 4, 2024 / Updated: April 18, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient limitations placed on the amount of CONTINUATION frames that can be sent within a single HTTP/2 stream. A remote attacker can send specially crafted HTTP/2 requests to the server and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Fedora
trafficserver (Debian package)
trafficserver
How to mitigate CVE-2024-31309
trafficserver (Debian package) - addressed in versions 8.1.10+ds-1~deb11u1, 9.2.4+ds-0+deb12u1
trafficserver - addressed in versions 9.2.4-1.el7, 9.2.4-1.el8, 9.2.4-1.el9, 9.2.4-1.fc38, 9.2.4-1.fc39, 9.2.4-1.fc40