60
CVE-2020-11993
PoC —CVSS 3.1
7.5 high
EPSS
56%p99
Published
()
Modified
Description
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
- Vendors
- apachenetappcanonicalopensusedebianfedoraprojectoracle
- Products
- http server, clustered data ontap, ubuntu linux, leap, debian linux, fedora, communications element manager, communications session report manager, communications session route manager, enterprise manager ops center, hyperion infrastructure technology, instantis enterprisetrack
- Weakness
- CWE-444
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H