VDB
CVE-2024-30156
CVE-2024-30156
PUBLISHED
Es besteht eine Schwachstelle in Varnish HTTP Cache. Dieser Fehler besteht auf Varnish Cacher-Servern, die das HTTP/2-Protokoll aktiviert haben, und ermöglicht es, dass das HTTP/2-Verbindungskontrollflussfenster des Servers keine Credits mehr hat, was dazu führt, dass kein Fortschritt bei der Verarbeitung von Streams gemacht wird, während die zugehörigen Ressourcen gehalten werden. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um einen Denial-of-Service-Zustand zu verursachen.
EPSS 0.07% · 21.9th percentile
Risk Scores
EPSS Score
0.07%
21.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Linux | |
| Red Hat | Red Hat Enterprise Linux | |
| RESF | RESF Rocky Linux | |
| Open Source | Open Source Varnish HTTP Cache <7.3.2 | |
| Open Source | Open Source Varnish HTTP Cache <7.4.3 | |
| Open Source | Open Source Varnish HTTP Cache <Enterprise 6.0.12r6 | |
| Open Source | Open Source Varnish HTTP Cache <6.0.13 |
Timeline
- Mar 24, 2024 CVE Published
- Mar 24, 2024 EPSS Score
- Apr 19, 2024 EPSS Score
- May 14, 2024 EPSS Score
- Jun 9, 2024 EPSS Score
- Jul 4, 2024 EPSS Score
- Aug 29, 2024 EPSS Score
- Sep 23, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 19, 2024 EPSS Score
- Nov 13, 2024 EPSS Score
- Nov 21, 2024 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0701.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0701 advisory
- https://varnish-cache.org/security/VSV00014.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-30156 advisory
- https://github.com/advisories/GHSA-c3wj-m54r-wfgq advisory
- https://access.redhat.com/errata/RHSA-2024:1690 advisory
- https://access.redhat.com/errata/RHSA-2024:1691 advisory
- https://access.redhat.com/errata/RHSA-2024:1689 advisory
- https://linux.oracle.com/errata/ELSA-2024-1690.html advisory
- https://linux.oracle.com/errata/ELSA-2024-1691.html advisory
- https://access.redhat.com/errata/RHSA-2024:2700 advisory
- https://errata.build.resf.org/RLSA-2024:1690 advisory
- https://access.redhat.com/errata/RHSA-2024:2820 advisory
- https://access.redhat.com/errata/RHSA-2024:2938 advisory
- https://access.redhat.com/errata/RHSA-2024:3305 advisory
- https://access.redhat.com/errata/RHSA-2024:3426 advisory
- https://access.redhat.com/errata/RHSA-2024:4937 advisory