Skip to content

fix to CVE-2023-44487#355

Merged
openshift-merge-bot[bot] merged 1 commit intoopendatahub-io:mainfrom
Jooho:fix-cve-2023-44487-odh
Jun 10, 2025
Merged

fix to CVE-2023-44487#355
openshift-merge-bot[bot] merged 1 commit intoopendatahub-io:mainfrom
Jooho:fix-cve-2023-44487-odh

Conversation

@Jooho
Copy link

@Jooho Jooho commented Jun 10, 2025

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
https://www.cve.org/CVERecord?id=CVE-2023-44487
https://app.snyk.io/org/red-hat-openshift-data-science-rhods/project/9509bf16-bf50-489f-8901-3dfe7a8c8819

Signed-off-by: Jooho Lee <jlee@redhat.com>
@Jooho Jooho force-pushed the fix-cve-2023-44487-odh branch from 40ba32e to 1deb832 Compare June 10, 2025 18:24
Copy link
Member

@spolti spolti left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci
Copy link

openshift-ci bot commented Jun 10, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Jooho, spolti

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot openshift-merge-bot bot merged commit 4e4afed into opendatahub-io:main Jun 10, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants