Skip to main content
Version: latest

CVE-2023-44487

CVE Details

CVE-2023-44487

Last Update

8/16/2024

NIST CVE Summary

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Our Official Summary

The CVE reported in coredns and kube-vip. Govulncheck reports it as non-impacting.

CVE Severity

7.5

Status

Ongoing

Affected Products & Versions

  • Palette VerteX airgap 4.4.11, 4.4.14

Revision History

  • 1.0 07/16/2024 Initial Publication
  • 2.0 08/16/2024 Added Palette VerteX airgap 4.4.14 to Affected Products