QID 87552
QID 87552: Apache Traffic Server Denial of Service (DoS) Vulnerability (CVE-2024-31309)
Apache Traffic Server is a fast, scalable and extensible HTTP/1.1 and HTTP/2.0 compliant caching proxy server.
CVE-2024-31309: ATS is vulnerable to a HTTP/2 CONTINUATION frame flooding attack.
Version Affected:
ATS 8.0.0 to 8.1.9
ATS 9.0.0 to 9.2.3
QID Detection Logic:
This unauthenticated QID relies on the version reported by the ATS service.
Successful exploitation of this vulnerability can cause Apache Traffic Server to consume more resources on the server.
Solution
Customers are advised to upgrade to Apache Traffic Server or later versions to remediate these vulnerabilities.
Workaround:
Users can set a new setting (proxy.config.http2.max_continuation_frames_per_minute) to limit the number of CONTINUATION frames per minute.
Vendor References
- Apache Traffic Server Reference -
lists.apache.org/thread/f9qh3g3jvy153wh82pz4onrfj1wh13kc
CVEs related to QID 87552
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Traffic Server Reference |
|