PT-2024-2589 · Apache · Apache Traffic Server

Bartek Nowotarski

·

Published

2024-01-05

·

Updated

2025-06-03

·

CVE-2024-31309

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Traffic Server versions 8.0.0 through 8.1.9 Apache Traffic Server versions 9.0.0 through 9.2.3
Description The HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. This issue is related to the incorrect determination of the end of a header when processing CONTINUATION frames, which can lead to an uncontrolled consumption of resources. A remote attacker can exploit this issue by sending multiple HTTP packets, potentially causing a denial of service.
Recommendations For versions 8.0.0 through 8.1.9, upgrade to version 8.1.10. For versions 9.0.0 through 9.2.3, upgrade to version 9.2.4. As a temporary workaround, consider setting a new setting proxy.config.http2.max continuation frames per minute to limit the number of CONTINUATION frames per minute.

Fix

DoS

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02651
CVE-2024-31309
DLA-3799-1
DSA-5659-1

Affected Products

Apache Traffic Server