Skip to content

Comment on HTTP/2 rapid reset attack impacting Nginx productsparent

Comments

I'm not saying there isn't a difference.

OP mentioned they didn't find Nginx listed on the CVE, and the reply said

If you read the article, you'll see that the default configuration is not affected.

Which, in the context of OPs comment, implies that the CVE wouldn't be associated because the default config is not affected.

Hence my reply that CVEs don't care whether its default config or not. If there is a CVE associated with the program, there is a CVE associated with the program, rare config or not.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.