CVE-2020-11080 (CNNVD-202006-293)
中文标题:
HTTP/2 资源管理错误漏洞
英文标题:
Denial of service in nghttp2
漏洞描述
中文描述:
HTTP/2是超文本传输协议的第二版,主要用于保证客户机与服务器之间的通信。 HTTP/2 1.41.0之前版本中存在资源管理错误漏洞。攻击者可借助恶意的客户端构建14,400字节长度的SETTINGS帧利用该漏洞造成拒绝服务。
英文描述:
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| nghttp2 | nghttp2 | < 1.41.0 | - | - |
cpe:2.3:a:nghttp2:nghttp2:<_1.41.0:*:*:*:*:*:*:*
|
| nghttp2 | nghttp2 | * | - | - |
cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*
|
| debian | debian_linux | 9.0 | - | - |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
| debian | debian_linux | 10.0 | - | - |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
| opensuse | leap | 15.1 | - | - |
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 31 | - | - |
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 33 | - | - |
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
|
| oracle | banking_extensibility_workbench | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_extensibility_workbench | 14.4.0 | - | - |
cpe:2.3:a:oracle:banking_extensibility_workbench:14.4.0:*:*:*:*:*:*:*
|
| oracle | blockchain_platform | * | - | - |
cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*
|
| oracle | enterprise_communications_broker | 3.1.0 | - | - |
cpe:2.3:a:oracle:enterprise_communications_broker:3.1.0:*:*:*:*:*:*:*
|
| oracle | enterprise_communications_broker | 3.2.0 | - | - |
cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:*:*:*:*:*
|
| oracle | graalvm | 19.3.2 | - | - |
cpe:2.3:a:oracle:graalvm:19.3.2:*:*:*:enterprise:*:*:*
|
| oracle | graalvm | 20.1.0 | - | - |
cpe:2.3:a:oracle:graalvm:20.1.0:*:*:*:enterprise:*:*:*
|
| oracle | mysql | * | - | - |
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
|
| nodejs | node.js | * | - | - |
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-11080 |
2025-11-11 15:20:20 | 2025-11-11 07:35:58 |
| NVD | nvd_CVE-2020-11080 |
2025-11-11 14:56:59 | 2025-11-11 07:44:26 |
| CNNVD | cnnvd_CNNVD-202006-293 |
2025-11-11 15:10:26 | 2025-11-11 07:56:15 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-202006-293
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 16
- data_sources: ['cve'] -> ['cve', 'nvd']