HTTP/2 Cleartext Detection

info Nessus Plugin ID 85805

Synopsis

An HTTP/2 server is listening on the remote host.

Description

The remote host is running an HTTP server that supports HTTP/2 running over cleartext TCP (h2c).

Solution

Limit incoming traffic to this port if desired.

See Also

https://http2.github.io/

https://tools.ietf.org/html/rfc7540

https://github.com/http2/http2-spec

Plugin Details

Severity: Info

ID: 85805

File Name: http_h2c_detect.nasl

Version: 1.8

Type: remote

Family: Web Servers

Published: 9/4/2015

Updated: 4/11/2022

Configuration: Enable thorough checks

Asset Inventory: true

Supported Sensors: Nessus