Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| Metrics |
ssvc
|
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-21T19:12:19.270Z
Reserved: 2024-03-24T00:00:00
Link: CVE-2024-30156
Updated: 2024-08-02T01:25:03.059Z
Status : Awaiting Analysis
Published: 2024-03-24T01:15:45.530
Modified: 2024-11-21T20:15:40.067
Link: CVE-2024-30156
OpenCVE Enrichment
No data.