← Back

CVE-2018-17189

nvd nist
Published: Jan 30, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

Affected (33)

Show all products
1 product
Http Server
2 products
Santricity Cloud Connector
Storage Automation Store
1 product
Fedora
1 product
Debian Linux
5 products
Enterprise Manager Ops Center
Hospitality Guest Access
Instantis Enterprisetrack
Retail Xstore Point Of Service
Sun Zfs Storage Appliance Kit
1 product
Ubuntu Linux
1 product
Jboss Core Services
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 2.4.17
Version 2.4.18
Version 2.4.20
Version 2.4.23
Version 2.4.25
Version 2.4.26
Version 2.4.27
Version 2.4.28
Version 2.4.29
Version 2.4.30
Version 2.4.33
Version 2.4.34
Version 2.4.35
Version 2.4.37
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 28
Version 29
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration E
9 vulnerable
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 18.10
Configuration G
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 1.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0
Redhat
Enterprise Linux
Version 7.0

References (60)

Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Vendor Advisory
Source: security@apache.org
Issue TrackingMailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.