Skip to content

[Spike] Check if we need to explicitly disable HTTP/2 to mitigate CVE-2023-44487 (Rapid Reset) #1315

Closed
@rm3l

Description

@rm3l

/kind task

As part of #1303, we'll need to bump a few of our dependencies across several repos.
But even doing so might not be sufficient to mitigate the HTTP/2 Rapid Reset vuln (CVE-2023-44487).
The scope of this issue is to check whether we also need to explicitly disable HTTP/2 as an additional safety measure.

If the answer is yes, we'll need to create follow-up issues.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

Status

Done ✅

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions