Skip to content

Allow HTTP/2 rate control to mitigate HTTP/2 floods (CVE-2023-44487) #10679

@sbordet

Description

@sbordet

Jetty version(s)
10+

Enhancement Description
Review HTTP/2 rate control in light of CVE-2023-44487, possibly incrementing the default rate.

(in case github/advisory-database#2869 isn't fixed, use top level link https://nvd.nist.gov/vuln/detail/CVE-2023-44487)

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions