Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4, or later versions.
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.7"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*"
}