V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-9514
DEB
High

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of str…

CVSS
7.5
High
EPSS
0.83
p99
Published
2019-01-01
Updated
2019-01-01
Description

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

Tags · CWE
Pre-auth
CWE-400
CAPEC-147
CAPEC-227
CAPEC-492
Affected products
Ansible-operatorAnsible-service-brokerAnsible-service-brokerApbApbApbAtomic-enterprise-service-catalogAtomic-enterprise-service-catalogAtomic-openshiftAtomic-openshiftAtomic-openshiftAtomic-openshift-cluster-autoscalerAtomic-openshift-deschedulerAtomic-openshift-deschedulerAtomic-openshift-dockerregistryAtomic-openshift-metrics-serverAtomic-openshift-node-problem-detectorAtomic-openshift-node-problem-detectorAtomic-openshift-service-idlerAtomic-openshift-web-console
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.828 · p99
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
ansible-operatorTracked
ansible-service-brokerTracked
ansible-service-brokerTracked
apbTracked
apbTracked
apbTracked
atomic-enterprise-service-catalogTracked
atomic-enterprise-service-catalogTracked
atomic-openshiftTracked
atomic-openshiftTracked
atomic-openshiftTracked
atomic-openshift-cluster-autoscalerTracked
atomic-openshift-deschedulerTracked
atomic-openshift-deschedulerTracked
atomic-openshift-dockerregistryTracked
atomic-openshift-metrics-serverTracked
atomic-openshift-node-problem-detectorTracked
atomic-openshift-node-problem-detectorTracked
atomic-openshift-service-idlerTracked
atomic-openshift-web-consoleTracked
Showing first 20 of 373
Source databases
DEB
MSR
CVE
RED
UBU
Related vulnerabilities