← All CVEs

CVE-2018-17189

medium · 5.3

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

5.3
CVSS
20.1%
EPSS (exploit prob.)
97th
EPSS percentile
2019-01-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
apachehttp_server2.4.17
apachehttp_server2.4.18
apachehttp_server2.4.20
apachehttp_server2.4.23
apachehttp_server2.4.25
apachehttp_server2.4.26
apachehttp_server2.4.27
apachehttp_server2.4.28
apachehttp_server2.4.29
apachehttp_server2.4.30
apachehttp_server2.4.33
apachehttp_server2.4.34
apachehttp_server2.4.35
apachehttp_server2.4.37
netappsantricity_cloud_connectorall versions
netappstorage_automation_storeall versions
fedoraprojectfedora28
fedoraprojectfedora29
debiandebian_linux9.0
oracleenterprise_manager_ops_center12.3.3
oraclehospitality_guest_access4.2.0
oraclehospitality_guest_access4.2.1
oracleinstantis_enterprisetrack17.1
oracleinstantis_enterprisetrack17.2
oracleinstantis_enterprisetrack17.3
oracleretail_xstore_point_of_service7.0
oracleretail_xstore_point_of_service7.1
oraclesun_zfs_storage_appliance_kit8.8.6
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux18.10
redhatjboss_core_services1.0
redhatenterprise_linux6.0
redhatenterprise_linux7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-17189