Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24155
HistoryApr 10, 2020 - 12:47 a.m.

Denial Of Service (DoS)

2020-04-1000:47:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.112 Low

EPSS

Percentile

95.2%

httpd is vulnerable to denial of service. It was discovered that mod_proxy_ajp incorrectly returned an “Internal Server Error” response when processing certain malformed requests, which caused the back-end server to be marked as failed in configurations where mod_proxy is used in load balancer mode. A remote attacker could cause mod_proxy to not send requests to back-end AJP (Apache JServ Protocol) servers for the retry timeout period (60 seconds by default) by sending specially-crafted requests.

References