CVE-2018-8011

HIGH EXPLOITED NUCLEI

Apache HTTP Server <2.4.34 - Use After Free

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-8011 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).

Nuclei Templates (1)

Apache HTTP Server - NULL Pointer Dereference
HIGHVERIFIEDby daffainfo
Shodan: cpe:"cpe:2.3:a:apache:http_server"

References (15)

Core 15
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041401
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180926-0007/

Scores

CVSS v3 7.5
EPSS 0.5171
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2022-02-22
CWE
CWE-476
Status published
Products (2)
apache/http_server 2.4.33
netapp/cloud_backup
Published Jul 18, 2018
Tracked Since Feb 18, 2026