Description
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
References
Related Vulnerabilities
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5489)
WordPress Plugin WordPress Shortcodes-Shortcodes Ultimate Remote Code Execution (5.0.0)
Drupal Core 4.7.x Form Action Attribute Injection (4.7.0 - 4.7.3)
MySQL CVE-2018-2775 Vulnerability (CVE-2018-2775)
Jenkins Incorrect Authorization Vulnerability (CVE-2023-27899)