Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9fg-6rr5-38xc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

Ссылки

EPSS

Процентиль: 75%
0.00935
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

CVSS3: 7.5
redhat
больше 4 лет назад

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

CVSS3: 7.5
nvd
больше 4 лет назад

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

CVSS3: 7.5
msrc
больше 4 лет назад

Request splitting via HTTP/2 method injection and mod_proxy

CVSS3: 7.5
debian
больше 4 лет назад

A crafted method sent through HTTP/2 will bypass validation and be for ...

EPSS

Процентиль: 75%
0.00935
Низкий

7.5 High

CVSS3