Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-770 | |
Metrics |
ssvc
|
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-24T00:00:00
Updated: 2024-11-21T19:12:19.270Z
Reserved: 2024-03-24T00:00:00
Link: CVE-2024-30156
Vulnrichment
Updated: 2024-08-02T01:25:03.059Z
NVD
Status : Awaiting Analysis
Published: 2024-03-24T01:15:45.530
Modified: 2024-11-21T20:15:40.067
Link: CVE-2024-30156
Redhat