Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade aws-nitro-enclaves-cliUpgrade aws-nitro-enclaves-cli-integration-testsUpgrade aws-nitro-enclaves-cli-develUpgrade aws-nitro-enclaves-cli-debuginfo | Mar 22, 2023 | Feb 21, 2023 |
| Amazon_linux_2023 | — | Upgrade aws-nitro-enclaves-cli-develUpgrade aws-nitro-enclaves-cliUpgrade aws-nitro-enclaves-cli-integration-tests | Feb 17, 2025 | Feb 21, 2023 |
| Debian | — | Upgrade rust-hyper | Jul 30, 2024 | Feb 21, 2023 |
| Suse | — | Upgrade aws-nitro-enclaves-cliUpgrade gstreamer-plugins-rs-develUpgrade rustupUpgrade system-group-neUpgrade sccacheUpgrade gstreamer-plugins-rsUpgrade aws-nitro-enclaves-binaryblobs-upstream | Apr 17, 2023 | Feb 21, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub