CVE-2020-1934

Modified
Published: 01 Apr 2020, 19:22
Last modified:04 Aug 2024, 06:54

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
27.24% HIGH
27% probability -14.63%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Apr 2020, 19:22
Published
Vulnerability first disclosed
04 Aug 2024, 06:54
Last Modified
Vulnerability information updated

Description

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 27.24% Percentile: 96%

Techniques & Countermeasures

  • CWE-908Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

Affected Systems

  • apacheapache_http_server

    2.4.0 to 2.4.41

  • UnknownHTTP Server

    ≥ 2.4.0, ≤ 2.4.41

  • canonicalubuntu_linux

    16.04 | 18.04 | 20.04

  • debiandebian_linux

    9.0 | 10.0

  • fedoraprojectfedora

    31 | 32

  • opensuseleap

    15.1

  • oraclecommunications_element_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_session_report_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_session_route_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oracleenterprise_manager_ops_center

    12.4.0.0

  • oracleinstantis_enterprisetrack

    ≥ 17.1, ≤ 17.3

  • oraclezfs_storage_appliance_kit

    8.8

References (23)