Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12542
HistoryJan 15, 2019 - 9:18 a.m.

Denial Of Service (DoS)

2019-01-1509:18:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

0.003 Low

EPSS

Percentile

68.0%

httpd is vulnerable to denial of service (DoS) attacks. The vulnerability exists as Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.

References