ZeroHour

CVE-2018-1333

CVSS 3.0
7.5 high
EPSS
17%p97
Published
()
Modified
Description

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

Vendors
apacheredhatcanonicalnetapp
Products
http server, jboss core services, ubuntu linux, cloud backup, storage automation store
Weakness
CWE-400
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.