CVE-2018-1333

HIGH

Apache HTTP Server 2.4.18-2.4.30,2.4.33 - Denial of Service via HTTP/2 Request Handling

Title source: llm
STIX 2.1

Description

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

References (21)

Core 21
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:3558
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0367
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180926-0007/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3783-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041402
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0366
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2019-09

Scores

CVSS v3 7.5
EPSS 0.2081
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (6)
apache/http_server 2.4.33
apache/http_server 2.4.18 - 2.4.30
canonical/ubuntu_linux 18.04
netapp/cloud_backup
netapp/storage_automation_store
redhat/jboss_core_services 1.0
Published Jun 18, 2018
Tracked Since Feb 18, 2026