CVE-2018-11763

MEDIUM EXPLOITED

Apache HTTP Server 2.4.17-2.4.34 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-11763 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.

References (26)

Core 26
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:3558
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105414
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190204-0004/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0367
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3783-1/
Vendor Advisory x_refsource_confirm
https://httpd.apache.org/security/vulnerabilities_24.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041713
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0366
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2019-09

Scores

CVSS v3 5.9
EPSS 0.2236
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2022-02-22
Status published
Products (17)
apache/http_server 2.4.17 - 2.4.34
canonical/ubuntu_linux 18.04
netapp/storage_automation_store
oracle/enterprise_manager_ops_center 12.3.3
oracle/hospitality_guest_access 4.2.0
oracle/hospitality_guest_access 4.2.1
oracle/instantis_enterprisetrack 17.1
oracle/instantis_enterprisetrack 17.2
oracle/instantis_enterprisetrack 17.3
oracle/retail_xstore_point_of_service 7.0
... and 7 more
Published Sep 25, 2018
Tracked Since Feb 18, 2026