Описание
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
A flaw was found in Apache httpd in versions 2.4.32 to 2.4.46. The uwsgi protocol does not serialize more than 16K of HTTP header leading to resource exhaustion and denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Отчет
Red Hat Enterprise Linux 5, 6, and 7 do not ship the vulnerable version of httpd and, thus, are not affected.
Меры по смягчению последствий
This flaw only affects specific httpd configurations which use the uwsgi protocol. It does not manifest itself when uwsgi protocol is not used. Commenting out "LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so" in /etc/httpd/conf.modules.d/00-proxy.conf will disable the loading of the vulnerable module.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | httpd | Not affected | ||
Red Hat Enterprise Linux 6 | httpd | Not affected | ||
Red Hat Enterprise Linux 7 | httpd | Not affected | ||
Red Hat JBoss Enterprise Web Server 2 | httpd | Out of support scope | ||
JBoss Core Services on RHEL 6 | jbcs-httpd24-apr | Fixed | RHSA-2020:4384 | 28.10.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-util | Fixed | RHSA-2020:4384 | 28.10.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-brotli | Fixed | RHSA-2020:4384 | 28.10.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-curl | Fixed | RHSA-2020:4384 | 28.10.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd | Fixed | RHSA-2020:4384 | 28.10.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-jansson | Fixed | RHSA-2020:4384 | 28.10.2020 |
Показывать по
Дополнительная информация
Статус:
9.8 Critical
CVSS3
Связанные уязвимости
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure an ...
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
9.8 Critical
CVSS3