CVE-2024-8062: Denial of Service in h2oai/h2o-3
A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a HEAD request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8062?
CVE-2024-8062 is classified as a denial of service vulnerability, which can disrupt the availability of the affected service.
How do I fix CVE-2024-8062?
To mitigate CVE-2024-8062, update h2oai/h2o-3 to a version that has addressed this vulnerability.
What software is affected by CVE-2024-8062?
CVE-2024-8062 affects h2oai/h2o-3 version 3.46.0.
What type of attack can exploit CVE-2024-8062?
CVE-2024-8062 can be exploited through a denial of service attack by sending multiple requests to the typeahead endpoint.
Can CVE-2024-8062 be exploited remotely?
Yes, CVE-2024-8062 can be exploited remotely by an attacker sending crafted requests without needing physical access to the network.