A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
2021-08-16T08:15:11.480
2025-05-01T15:40:12.163
Analyzed
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | debian | debian_linux | 10.0 | Yes |
| Application | apache | http_server | < 2.4.49 | Yes |
| Operating System | fedoraproject | fedora | 34 | Yes |
| Operating System | fedoraproject | fedora | 35 | Yes |
| Application | tenable | tenable.sc | ≤ 5.19.1 | Yes |
| Application | oracle | secure_backup | < 18.1.0.1.0 | Yes |
| Application | oracle | zfs_storage_appliance_kit | 8.8 | Yes |