CVE-2024-31309

Name
CVE-2024-31309
Description
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server.  Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute.  ATS does have a fixed amount of memory a request can use and ATS adheres to these limits in previous releases. Users are recommended to upgrade to versions 8.1.10 or 9.2.4 which fixes the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://lists.apache.org/thread/f9qh3g3jvy153wh82pz4onrfj1wh13kc
security@apache.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QV77HYM7ARSTL3B6U3IFG7PHDU65WL4I/
security@apache.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3XON6RM5ZKCZ6K6NB7BOTAWMJQKXJDO/
security@apache.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBKLPQ6ECG4PGEPRCYI3Y3OITNDEFCCV/
security@apache.org https://lists.debian.org/debian-lts-announce/2024/04/msg00021.html
security@apache.org http://www.openwall.com/lists/oss-security/2024/04/03/16
security@apache.org http://www.openwall.com/lists/oss-security/2024/04/10/7
af854a3a-2127-422b-91ae-364da2661108 https://www.kb.cert.org/vuls/id/421644

Match rules

CPE URI Source package Min version Max version
apache-traffic-server >= 8.0.0 <= 8.1.9
apache-traffic-server >= 9.0.0 <= 9.2.3
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* traffic_server >= 8.0.0 < 8.1.10
cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:* traffic_server >= 9.0.0 < 9.2.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
trafficserver9 edge-community 9.2.4-r0 None fixed
trafficserver9 3.22-community 9.2.4-r0 None fixed
trafficserver9 3.21-community 9.2.4-r0 None fixed