Описание
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 2.4.64-1ubuntu1 |
| esm-infra-legacy/trusty | not-affected | |
| esm-infra/bionic | released | 2.4.29-1ubuntu4.27+esm6 |
| esm-infra/focal | released | 2.4.41-4ubuntu3.23+esm2 |
| esm-infra/xenial | not-affected | |
| jammy | released | 2.4.52-1ubuntu4.15 |
| noble | released | 2.4.58-1ubuntu8.7 |
| plucky | released | 2.4.63-1ubuntu1.1 |
| upstream | released | 2.4.64-1 |
Показывать по
7.5 High
CVSS3
Связанные уязвимости
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
In certain proxy configurations, a denial of service attack againstApa ...
7.5 High
CVSS3