CVE-2023-41337 describes a vulnerability in h2o, an HTTP server, specifically affecting versions 2.3.0-beta2 and prior when configured with host-level listen directives for multiple addresses/ports and backend servers managed by different entities. An attacker, already acting as a backend, can misdirect and observe HTTPS requests by exploiting how h2o handles TLS session resumption without binding session IDs to server-specific information. This vulnerability has a CVSS score of 6.7 (MEDIUM), indicating an attack vector requiring adjacent network access and low privileges, but with high impact on confidentiality and integrity. The attack relies on user interaction (TLS session resumption) and a specific, vulnerable h2o configuration. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. A patch is available, and a workaround involves using global-level listen directives instead of host-level ones.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.6CPE matchmatch criteria | cpe:2.3:a:dena:h2o:*:*:*:*:*:*:*:* | ||
2.3.0CPE matchmatch criteria | cpe:2.3:a:dena:h2o:2.3.0:beta1:*:*:*:*:*:* | ||
2.3.0CPE matchmatch criteria | cpe:2.3:a:dena:h2o:2.3.0:beta2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.