CVE-2024-31079

CVSS V2 None CVSS V3 None
Description
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
Overview
  • CVE ID
  • CVE-2024-31079
  • Assigner
  • f5
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-29T16:02:04.620Z
  • Last Modified Date
  • 2024-05-29T16:02:04.620Z
History
Created Old Value New Value Data Type Notes
2024-06-25 22:59:43 Added to TrackCVE