ZeroHour

CVE-2018-11763

CVSS 3.0
5.9 medium
EPSS
51%p99
Published
()
Modified
Description

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.

Vendors
apachecanonicalredhatoraclenetapp
Products
http server, ubuntu linux, enterprise linux, enterprise manager ops center, hospitality guest access, instantis enterprisetrack, retail xstore point of service, secure global desktop, storage automation store
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.