cbcvebase.
CVE-2023-44487
published 2024-04-25

CVE-2023-44487: An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-31
Exploited in the wild
An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

Affected

320 ranges· showing 25
VendorProductVersion rangeFixed in
akkahttp_server< 10.5.310.5.3
amazonopensearch_data_prepper< 2.5.02.5.0
apacheapisix< 3.6.13.6.1
apachehttp_server>= 2.4.17 < 2.4.582.4.58
apachehttpd
apachesolr< 9.4.09.4.0
apachetomcat
apachetomcat
apachetomcat10.1.0 – 10.1.13
apachetomcat8.5.0 – 8.5.93
apachetomcat9.0.0 – 9.0.80
apachetraffic_server>= 8.0.0 < 8.1.98.1.9
apachetraffic_server>= 9.0.0 < 9.2.39.2.3
apache_software_foundationapache_http_server2.4.17 – 2.4.57
appleswiftnio_http_2< 1.28.01.28.0
atlassiancrowd
caddyservercaddy< 2.7.52.7.5
ciscobusiness_process_automation< 3.2.003.0093.2.003.009
ciscoconnected_mobile_experiences< 11.111.1
ciscocrosswork_data_gateway< 4.1.34.1.3
ciscocrosswork_data_gateway>= 5.0.0 < 5.0.25.0.2
ciscocrosswork_zero_touch_provisioning< 6.0.06.0.0
ciscoexpressway< x14.3.3x14.3.3
ciscofirepower_threat_defense< 7.4.27.4.2
ciscofog_director< 1.221.22

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH