Solved HTTP/2 Rapid Reset Vulnerability affecting NGINX (CVE-2023-44487)

Status
Not open for further replies.

Michael Menor

Silver Partner
Advanced Certified
Joined
Dec 30, 2016
Messages
83
Reaction score
4
Originally posted here last week. Ticket with 3CX still hasn't been looked at....

How does this affect NGINX in 3CX?

Researchers and vendors have disclosed a denial-of-service (DoS) vulnerability in HTTP/2 protocol. The vulnerability (CVE-2023-44487), known as Rapid Reset, has been exploited in the wild in August 2023 through October 2023.

CISA recommends organizations that provide HTTP/2 services apply patches when available and consider configuration changes and other mitigations discussed in the references below. For more information on Rapid Reset, see:
 
Hi there,

As per nginx's official statement, using the default configuration should be sufficient for mitigating this attack.

Given that we do not use a larger than the default keepalive_requests or http2_max_concurrent_streams value, it can be considered that the nginx config used in 3CX is currently not affected by this.

There isn't any patch available for nginx apt packages at the moment.
 
Status
Not open for further replies.