Описание
A vulnerability in the /3/ImportFiles endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, path, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.
Ссылки
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:h2o:h2o:3.46.1:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00137
Низкий
7.5 High
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 7.5
github
11 месяцев назад
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
EPSS
Процентиль: 34%
0.00137
Низкий
7.5 High
CVSS3
Дефекты
CWE-770