ZeroHour

CVE-2020-9490

CVSS 3.1
7.5 high
EPSS
89%p100
Published
()
Modified
Description

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.

Vendors
apacheoracleopensusedebianfedoraprojectcanonicalredhat
Products
http server, communications element manager, communications session report manager, communications session route manager, enterprise manager ops center, hyperion infrastructure technology, instantis enterprisetrack, zfs storage appliance kit, leap, debian linux, fedora, ubuntu linux
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news