Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review the possible impact of CVE-2023-44487 #220

Open
skounis opened this issue Oct 12, 2023 · 1 comment
Open

Review the possible impact of CVE-2023-44487 #220

skounis opened this issue Oct 12, 2023 · 1 comment
Labels
question Further information is requested

Comments

@skounis
Copy link

skounis commented Oct 12, 2023

Your Question

Review the CVE-2023-44487 and report on any impact on the function of the GW and possible mitigation actions (code changes?)

  • Source File:
  • Line(s):
  • Question:
@skounis skounis added the question Further information is requested label Oct 12, 2023
@skounis skounis assigned skounis and unassigned skounis Oct 12, 2023
@gstsec
Copy link

gstsec commented Oct 13, 2023

According to the information I got, Tomcat 10.1.5 is being used. This version is prone to CVE-2023-44487 and should be updated to 10.1.14 (cf. https://tomcat.apache.org/security-10.html).
nginx is only affected when the ngx_http_v2_module] is deployed (https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants