CVE-2018-17189

Modified
Published: 30 Jan 2019, 22:00
Last modified:17 Sept 2024, 01:21

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
7.67% LOW
8% probability +3.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jan 2019, 22:00
Published
Vulnerability first disclosed
17 Sept 2024, 01:21
Last Modified
Vulnerability information updated

Description

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 7.67% Percentile: 92%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • apache software foundationapache http server

    2.4.17 to 2.4.37

  • UnknownHTTP Server

    2.4.17 | 2.4.18 | 2.4.20 | 2.4.23 | 2.4.25 | 2.4.26 | 2.4.27 | 2.4.28 | 2.4.29 | 2.4.30 | 2.4.33 | 2.4.34 | 2.4.35 | 2.4.37

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 18.10

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    28 | 29

  • netappsantricity_cloud_connector

    na

  • netappstorage_automation_store

    na

  • oracleenterprise_manager_ops_center

    12.3.3

  • oraclehospitality_guest_access

    4.2.0 | 4.2.1

  • oracleinstantis_enterprisetrack

    17.1 | 17.2 | 17.3

  • oracleretail_xstore_point_of_service

    7.0 | 7.1

  • oraclesun_zfs_storage_appliance_kit

    8.8.6

  • redhatjboss_core_services

    1.0

References (30)