CVE-2018-17189
—CVSS 3.1
5.3 medium
EPSS
20%p97
Published
()
Modified
Description
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
- Vendors
- apachenetappfedoraprojectdebianoraclecanonicalredhat
- Products
- http server, santricity cloud connector, storage automation store, fedora, debian linux, enterprise manager ops center, hospitality guest access, instantis enterprisetrack, retail xstore point of service, sun zfs storage appliance kit, ubuntu linux, jboss core services
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.