Lucene search

K
cvelistApacheCVELIST:CVE-2018-1333
HistoryJul 17, 2018 - 12:00 a.m.

CVE-2018-1333 DoS for HTTP/2 connections by crafted requests

2018-07-1700:00:00
apache
www.cve.org
3

7.3 High

AI Score

Confidence

High

0.067 Low

EPSS

Percentile

93.9%

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

CNA Affected

[
  {
    "product": "Apache HTTP Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33)"
      }
    ]
  }
]

References