Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26304
HistoryAug 11, 2020 - 3:22 a.m.

Denial Of Service (DoS)

2020-08-1103:22:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
apache
http/2
denial of service

EPSS

0.007

Percentile

80.3%

apache is vulnerable to denial of service (DoS). The vulnerability exists as a specially crafted value for the ‘Cache-Digest’ header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via “H2Push off” will mitigate this vulnerability for unpatched servers.

References