CVE-2024-31309
Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
Record summary
CVE-2024-31309 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC.
Description
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute. ATS does have a fixed amount of memory a request can use and ATS adheres to these limits in previous releases. Users are recommended to upgrade to versions 8.1.10 or 9.2.4 which fixes the issue.
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Apache Traffic ServerBrowse Apache Software Foundation / Apache Traffic ServerDefault status: unaffected | CVE List | 8.0.0 to ≤ 8.1.9 | affected |
| 9.0.0 to ≤ 9.2.3 | affected | ||
traffic_serverBrowse apache / traffic_serverDefault status: unknown | CVE List | 8.0.0 to ≤ 8.1.9 | affected |
| 9.0.0 to ≤ 9.2.3 | affected |