Candidate: CVE-2019-10079 PublicDate: 2019-10-22 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10079 https://lists.apache.org/thread.html/d0e00f2e147a9e9b13a6829133092f349b2882bf6860397368a52600@%3Cannounce.tomcat.apache.org%3E Description: Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4, or later versions. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_trafficserver: upstream_trafficserver: needs-triage precise/esm_trafficserver: DNE trusty_trafficserver: ignored (out of standard support) trusty/esm_trafficserver: DNE xenial_trafficserver: ignored (end of standard support, was needs-triage) bionic_trafficserver: needs-triage disco_trafficserver: ignored (reached end-of-life) eoan_trafficserver: not-affected (8.0.5+ds-1) focal_trafficserver: not-affected (8.0.5+ds-2) groovy_trafficserver: not-affected (8.0.5+ds-2) hirsute_trafficserver: not-affected (8.0.5+ds-2) impish_trafficserver: not-affected (8.0.5+ds-2) jammy_trafficserver: not-affected (8.0.5+ds-2) devel_trafficserver: not-affected (8.0.5+ds-2)