Stateward All advisories →
medium
exploited in the wild
CVE-2023-44487
Maven · org.apache.tomcat:tomcat-coyote • Maven · org.apache.tomcat.embed:tomcat-embed-core • Maven · org.eclipse.jetty.http2:http2-common • Maven · org.eclipse.jetty.http2:http2-server • Maven · org.eclipse.jetty.http2:jetty-http2-common • Maven · org.eclipse.jetty.http2:jetty-http2-server • Maven · com.typesafe.akka:akka-http-core • Maven · com.typesafe.akka:akka-http-core_2.13 • Maven · com.typesafe.akka:akka-http-core_2.12 • Maven · com.typesafe.akka:akka-http-core_2.11 • Go · golang.org/x/net
Summary HTTP/2 Stream Cancellation Attack
Severity medium EPSS 100.0% (p100) Also known as GHSA-qppj-fm5r-hxr3, GHSA-qppj-fm5r-hxr3#com.typesafe.akka:akka-http-core, GHSA-qppj-fm5r-hxr3#com.typesafe.akka:akka-http-core_2.11, GHSA-qppj-fm5r-hxr3#com.typesafe.akka:akka-http-core_2.12, GHSA-qppj-fm5r-hxr3#com.typesafe.akka:akka-http-core_2.13, GHSA-qppj-fm5r-hxr3#org.apache.tomcat:tomcat-coyote, GHSA-qppj-fm5r-hxr3#org.apache.tomcat.embed:tomcat-embed-core, GHSA-qppj-fm5r-hxr3#org.eclipse.jetty.http2:http2-common, GHSA-qppj-fm5r-hxr3#org.eclipse.jetty.http2:http2-server, GHSA-qppj-fm5r-hxr3#org.eclipse.jetty.http2:jetty-http2-common, GHSA-qppj-fm5r-hxr3#org.eclipse.jetty.http2:jetty-http2-server, BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-tomcat-2023-44487, BIT-varnish-2023-44487 Published 2023-10-10
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repo