ZeroHour

CVE-2018-17189

CVSS 3.1
5.3 medium
EPSS
20%p97
Published
()
Modified
Description

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

Vendors
apachenetappfedoraprojectdebianoraclecanonicalredhat
Products
http server, santricity cloud connector, storage automation store, fedora, debian linux, enterprise manager ops center, hospitality guest access, instantis enterprisetrack, retail xstore point of service, sun zfs storage appliance kit, ubuntu linux, jboss core services
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.