ZeroHour

CVE-2019-0197

CVSS 3.1
4.2 medium
EPSS
9%p95
Published
()
Modified
Description

A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.

Vendors
apachecanonicalfedoraprojectopensuseredhatoracle
Products
http server, ubuntu linux, fedora, leap, jboss core services, communications session report manager, communications session route manager, enterprise manager ops center, instantis enterprisetrack, retail xstore point of service
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.