Lucene search

K
redhatcveRedhat.comRH:CVE-2019-5737
HistoryMar 01, 2020 - 7:37 a.m.

CVE-2019-5737

2020-03-0107:37:24
redhat.com
access.redhat.com
14

EPSS

0.013

Percentile

86.4%

It was found that the original fix for Slowloris, CVE-2018-12122, was insufficient. It is possible to bypass the server’s headersTimeout by sending two specially crafted HTTP requests in the same connection. An attacker could use this flaw to bypass Slowloris protection, resulting in a denial of service.

Mitigation

The use of a Load Balancer or a Reverse Proxy will increase the difficulty of the attack.