CVE-2020-9490
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Affected (50)
Products: Apache: Http Server · Oracle: Communications Element Manager, Communications Session Report Manager, Communications Session Route Manager, Enterprise Manager Ops Center, Hyperion Infrastructure Technology, Instantis Enterprisetrack, Zfs Storage Appliance Kit · Opensuse: Leap · +4 more
Show all products
Apache: Http Server · Oracle: Communications Element Manager, Communications Session Report Manager, Communications Session Route Manager, Enterprise Manager Ops Center, Hyperion Infrastructure Technology, Instantis Enterprisetrack, Zfs Storage Appliance Kit · Opensuse: Leap · Debian: Debian Linux · Fedoraproject: Fedora · Canonical: Ubuntu Linux · Redhat: Software Collections, Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Openstack, Openstack For Ibm Power
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.4.20 to 2.4.46 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.2.0 to 8.2.2 | |
| From 8.2.0 to 8.2.2 | |
| From 8.2.0 to 8.2.2 | |
| Version 12.4.0.0 | |
| Version 11.1.2.4 | |
| Version 17.1 | |
| Version 8.8 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 31 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.04 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.1 | |
| Version 8.0 | |
| Version 8.1 | |
| Version 8.0 | |
| Version 8.1 | |
| Version 8.2 | |
| Version 8.1 | |
| Version 8.2 | |
| Version 8.1 | |
| Version 16.1 | |
| Version 16.1 |
References (58)
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Vendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.