一、 漏洞 CVE-2023-44487 基础信息
漏洞标题
N/A
来源:AIGC 神龙大模型
漏洞描述信息
HTTP/2协议允许拒绝服务(服务器资源消耗),因为请求取消可以迅速重置许多流,如2023年8月至10月在野生中测试的。
来源:AIGC 神龙大模型
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
来源:AIGC 神龙大模型
漏洞类别
未加控制的资源消耗(资源穷尽)
来源:AIGC 神龙大模型
漏洞标题
N/A
来源:美国国家漏洞数据库 NVD
漏洞描述信息
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
来源:美国国家漏洞数据库 NVD
CVSS信息
N/A
来源:美国国家漏洞数据库 NVD
漏洞类别
N/A
来源:美国国家漏洞数据库 NVD
漏洞标题
Apache HTTP/2 资源管理错误漏洞
来源:中国国家信息安全漏洞库 CNNVD
漏洞描述信息
HTTP/2是超文本传输协议的第二版,主要用于保证客户机与服务器之间的通信。 Apache HTTP/2存在安全漏洞。攻击者利用该漏洞导致系统拒绝服务。以下产品和版本受到影响:.NET 6.0,ASP.NET Core 6.0,.NET 7.0,Microsoft Visual Studio 2022 version 17.2,Microsoft Visual Studio 2022 version 17.4,Microsoft Visual Studio 2022 version 17.6,Micros
来源:中国国家信息安全漏洞库 CNNVD
CVSS信息
N/A
来源:中国国家信息安全漏洞库 CNNVD
漏洞类别
资源管理错误
来源:中国国家信息安全漏洞库 CNNVD
二、漏洞 CVE-2023-44487 的公开POC
# POC 描述 源链接 神龙链接
1 Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487 https://github.com/bcdannyboy/CVE-2023-44487 POC详情
2 Proof of concept for DoS exploit https://github.com/imabee101/CVE-2023-44487 POC详情
3 Test Script for CVE-2023-44487 https://github.com/ByteHackr/CVE-2023-44487 POC详情
4 CVE-2023-44487 https://github.com/pabloec20/rapidreset POC详情
5 Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487) https://github.com/secengjeff/rapidresetclient POC详情
6 A python based exploit to test out rapid reset attack (CVE-2023-44487) https://github.com/studiogangster/CVE-2023-44487 POC详情
7 None https://github.com/ReToCode/golang-CVE-2023-44487 POC详情
8 HTTP/2 RAPID RESET https://github.com/sigridou/CVE-2023-44487 POC详情
9 Highly configurable tool to check a server's vulnerability against CVE-2023-44487 by rapidly sending HEADERS and RST_STREAM frames and documenting the server's responses. https://github.com/ndrscodes/http2-rst-stream-attacker POC详情
10 Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept https://github.com/nxenon/cve-2023-44487 POC详情
11 A tool to check how well a system can handle Rapid Reset DDoS attacks (CVE-2023-44487). https://github.com/terrorist/HTTP-2-Rapid-Reset-Client POC详情
12 None https://github.com/sigridou/CVE-2023-44487- POC详情
13 None https://github.com/TYuan0816/cve-2023-44487 POC详情
14 None https://github.com/sn130hk/CVE-2023-44487 POC详情
15 None https://github.com/threatlabindonesia/CVE-2023-44487-HTTP-2-Rapid-Reset-Exploit-PoC POC详情
16 RapidResetClient https://github.com/aulauniversal/CVE-2023-44487 POC详情
17 POC for CVE-2023-44487 https://github.com/BMG-Black-Magic/CVE-2023-44487 POC详情
18 Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487) https://github.com/internalwhel/rapidresetclient POC详情
三、漏洞 CVE-2023-44487 的情报信息