Логотип exploitDog
bind:CVE-2024-7768
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-7768

Количество 2

Количество 2

nvd логотип

CVE-2024-7768

11 месяцев назад

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p2vc-m5fv-9w9m

11 месяцев назад

H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-7768

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-p2vc-m5fv-9w9m

H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint

CVSS3: 7.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу