Description
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Remediation
References
Related Vulnerabilities
Jboss EAP CVE-2023-3223 Vulnerability (CVE-2023-3223)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-7861)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2242)
RubyGems Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-8324)