XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Undefined Undefined
    • 1.3.3
    • 1.3.1
    • Security, Service Binding
    • None
    • False
    • None
    • False
    • Hide
      Before this update an attacker could cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache was capped, an attacker sending very large keys could cause the server to allocate approximately 64 MiB per open connection.
      Show
      Before this update an attacker could cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache was capped, an attacker sending very large keys could cause the server to allocate approximately 64 MiB per open connection.
    • CVE - Common Vulnerabilities and Exposures
    • AppSvc Sprint 228

      Description of problem:

      https://nvd.nist.gov/vuln/detail/CVE-2022-41717

      Identified by:

      Prerequisites (if any, like setup, operators/versions):

      Steps to Reproduce

      1. <steps>

      Actual results:

      Expected results:

      Reproducibility (Always/Intermittent/Only Once):

      Build Details:

      Additional info:

      Documentation Requirement: Yes/No (needs-docs|upstream-docs / no-doc)

      Upstream: <Inputs/Requirement details>/ Not Applicable

      Downstream: <Type: Doc defect/More inputs to doc>/ Not Applicable

      Provide link to the relevant section
      Provide doc inputs and details required

      Release Notes Type: <New Feature/Enhancement/Known Issue/Bug
      fix/Breaking change/Deprecated Functionality/Technology Preview>

              pmacik@redhat.com Pavel Macik
              pmacik@redhat.com Pavel Macik
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: