CVE-2023-45802
Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2023-45802 is a vulnerability discovered in Apache HTTP Server's HTTP/2 implementation that affects versions 2.4.17 through 2.4.57. The vulnerability was identified during testing of CVE-2023-44487 (HTTP/2 Rapid Reset Exploit) and was disclosed in October 2023 (Vendor Advisory).

Technical details

When a HTTP/2 stream was reset (RST frame) by a client, there was a time window where the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. This implementation flaw allowed a client to send new requests and resets, keeping the connection busy and open, causing the memory footprint to continuously grow. The vulnerability has been assigned a CVSS v3.1 base score of 5.9 MEDIUM with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The primary impact of this vulnerability is potential denial of service through memory exhaustion. While all resources were eventually reclaimed on connection close, the process might run out of memory before that point. During normal HTTP/2 use, the probability of encountering this bug was considered very low, as the retained memory would not become noticeable before the connection closes or times out (Vendor Advisory).

Mitigation and workarounds

Users are recommended to upgrade to Apache HTTP Server version 2.4.58, which contains the fix for this vulnerability. The fix addresses the memory reclamation issue by ensuring proper resource cleanup when HTTP/2 streams are reset (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management