Lucene search

K
hackeroneHannoH1:269568
HistorySep 19, 2017 - 6:04 p.m.

Internet Bug Bounty: Optionsbleed / CVE-2017-9798

2017-09-1918:04:00
hanno
hackerone.com
$100
222

0.974 High

EPSS

Percentile

99.9%

Bug has been disclosed here:
https://blog.fuzzing-project.org/60-Optionsbleed-HTTP-OPTIONS-method-can-leak-Apaches-server-memory.html

poc code:
https://github.com/hannob/optionsbleed

Apache is currently preparing 2.4.28, which will contain the fix, a patch is available in their svn repo.