By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
2018-06-18T18:29:00.257
2024-11-21T03:59:38.603
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | http_server | ≤ 2.4.30 | Yes |
Application | apache | http_server | 2.4.33 | Yes |
Application | redhat | jboss_core_services | 1.0 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | No |
Operating System | redhat | enterprise_linux | 7.0 | No |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | storage_automation_store | - | Yes |