Lucene search

K
cvelistApacheCVELIST:CVE-2021-33193
HistoryAug 16, 2021 - 12:00 a.m.

CVE-2021-33193 Request splitting via HTTP/2 method injection and mod_proxy

2021-08-1600:00:00
apache
www.cve.org

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.3%

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache HTTP Server",
    "versions": [
      {
        "version": "Apache HTTP Server 2.4 2.4.17 to 2.4.48",
        "status": "affected"
      }
    ]
  }
]

References