ZeroHour

CVE-2021-33193

PoC
CVSS 3.1
7.5 high
EPSS
46%p99
Published
()
Modified
Description

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

Vendors
debianapachefedoraprojecttenableoracle
Products
debian linux, http server, fedora, tenable.sc, secure backup, zfs storage appliance kit
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.