Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-9511 PoC — Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potential

Source
Associated Vulnerability
Title: Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (CVE-2019-9511)
Description:Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Description
based on nginx 1.19.5 to fix for CVE-2018-16843, CVE-2018-16844, CVE-2019-9511, CVE-2019-9513, and CVE-2019-9516
Readme
BUILD:
```bash
cd ./ingress-nginx-0.21-1.19.5
cd images/nginx/
make
cd  -
cd images/e2e/
make docker-build
cd -
e2e_tag=`docker images|grep e2e|awk {'print  $2'}`
sed -i "s/e2e:v12232020-dce860a/e2e:$e2e_tag/" build/go-in-docker.sh
make


echo -e '\n\n\n\n\n'
docker images|grep  ingress-nginx
```

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →