cbcvebase.
CVE-2023-44487
published 2024-04-25

CVE-2023-44487: An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

PriorityP187high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-31
Exploited in the wild
EPSS
100.00%
100.0th percentile
An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

Affected

354 ranges· showing 25
VendorProductVersion rangeFixed in
akkahttp_server< 10.5.310.5.3
amazonopensearch_data_prepper< 2.5.02.5.0
apacheapisix< 3.6.13.6.1
apachehttp_server>= 2.4.17 < 2.4.582.4.58
apachehttpd
apachesolr< 9.4.09.4.0
apachetomcat
apachetomcat
apachetomcat10.1.0 – 10.1.13
apachetomcat8.5.0 – 8.5.93
apachetomcat9.0.0 – 9.0.80
apachetraffic_server>= 8.0.0 < 8.1.98.1.9
apachetraffic_server>= 9.0.0 < 9.2.39.2.3
appleswiftnio_http_2< 1.28.01.28.0
atlassiancrowd
caddyservercaddy< 2.7.52.7.5
ciscobusiness_process_automation< 3.2.003.0093.2.003.009
ciscoconnected_mobile_experiences< 11.111.1
ciscocrosswork_data_gateway< 4.1.34.1.3
ciscocrosswork_data_gateway>= 5.0.0 < 5.0.25.0.2
ciscocrosswork_zero_touch_provisioning< 6.0.06.0.0
ciscoexpressway< x14.3.3x14.3.3
ciscofirepower_threat_defense< 7.4.27.4.2
ciscofog_director< 1.221.22
ciscoios_xe< 17.15.117.15.1

Detection & IOCsextracted from sources · hover to see the quote

snort
62519
  • HTTP/2 Rapid Reset attack is performed by rapidly sending RST_STREAM frames after opening streams, causing server-side resource exhaustion. Detect abnormal rates of RST_STREAM frames per connection.
  • Monitor for HTTP/2 connections that rapidly open and cancel streams (RST_STREAM frames) at high rates — a botnet of only 20,000 machines achieved 200M+ rps using this technique.
  • Attacks caused a measurable increase in HTTP 502 errors at the proxy/upstream boundary — elevated 502 rates on HTTP/2 infrastructure may indicate an active Rapid Reset attack.
  • Apache Tomcat servers can be detected as vulnerable to CVE-2023-44487 via Qualys WAS QID 150732, detected based on installed version.
  • ·HTTP/2 Rapid Reset abuses the protocol's stream multiplexing and client-unilateral cancellation design; there is no single universal fix — mitigations are implementation-specific rate controls, not a protocol-level patch.
  • ·An incomplete fix was shipped for CVE-2023-44487 in OpenShift Containers (tracked separately as CVE-2023-6596); operators should verify their OpenShift patch is fully remediated.
  • ·Windows registry mitigations (Http2MaxClientResetsPerMinute / Http2MaxClientResetsGoaway) only apply to systems that have exposed a web server to the Internet; internal-only hosts do not require configuration.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_apache7.5
vendor_cisco7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.