Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2024-25678
Published:
Feb 09, 2024
| Modified:
Feb 15, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2024-25678
CWE
https://cwe.mitre.org/data/definitions/.html
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
Affected Software
Name
Vendor
Start Version
End Version
Lsquic
Litespeedtech
*
4.0.4 (excluding)
References
https://github.com/litespeedtech/lsquic/commit/515f453556c99d27c4dddb5424898dc1a5537708
https://github.com/litespeedtech/lsquic/releases/tag/v4.0.4
https://www.rfc-editor.org/rfc/rfc9001
Aqua Container Security