CVE-2018-11763
published 2018-09-25CVE-2018-11763: In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any…
PriorityP275medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
51.00%
98.8th percentile
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.4.17 – 2.4.34 | — |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.4.35-1 (bookworm) | apache2 2.4.35-1 (bookworm) |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | hospitality_guest_access | — | — |
| oracle | hospitality_guest_access | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | secure_global_desktop | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack targets only HTTP/2 (h2) connections; detection should focus on monitoring for continuous, large SETTINGS frames over HTTP/2 connections that never time out. ↗
- →More specifically, the attack uses SETTINGS frames sent at maximum size continuously; look for HTTP/2 SETTINGS frame floods from a single client connection. ↗
- ·The vulnerability only affects servers with the h2 protocol enabled. Disabling h2 is a possible mitigation. ↗
- ·Affected Apache httpd versions are 2.4.17 through 2.4.34 (specifically: 2.4.18, 2.4.20, 2.4.23, 2.4.25, 2.4.26, 2.4.27, 2.4.28, 2.4.29, 2.4.30, 2.4.33, 2.4.34). Fixed in 2.4.35 and mod_http2 1.11.0 and later. ↗
- ·Red Hat Enterprise Linux 7 and earlier httpd packages do not include HTTP/2 support and are therefore not affected. ↗
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vulncheck5.9MEDIUM
vendor_apache5.9LOW
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c8x9-mqh7-g47j: In Apache HTTP Server 2
ghsa_unreviewed·2022-05-13
CVE-2018-11763 [MEDIUM] GHSA-c8x9-mqh7-g47j: In Apache HTTP Server 2
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
OSV
apache2 vulnerabilities
osv·2018-10-03·CVSS 5.9
CVE-2018-1302 [MEDIUM] apache2 vulnerabilities
apache2 vulnerabilities
Robert Swiecki discovered that the Apache HTTP Server HTTP/2 module
incorrectly destroyed certain streams. A remote attacker could possibly
use this issue to cause the server to crash, leading to a denial of
service. (CVE-2018-1302)
Craig Young discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain requests. A remote attacker could possibly
use this issue to cause the server to consume resources, leading to a
denial of service. (CVE-2018-1333)
Gal Goldshtein discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled large SETTINGS frames. A remote attacker could possibly
use this issue to cause the server to consume resources, leading to a
denial of service. (CVE-2018-11763)
OSV
CVE-2018-11763: In Apache HTTP Server 2
osv·2018-09-25·CVSS 5.9
CVE-2018-11763 [MEDIUM] CVE-2018-11763: In Apache HTTP Server 2
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
VulnCheck
Apache HTTP Server SETTINGS Frames Vulnerability
vulncheck·2018·CVSS 5.9
CVE-2018-11763 [MEDIUM] Apache HTTP Server SETTINGS Frames Vulnerability
Apache HTTP Server SETTINGS Frames Vulnerability
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Affected: Apache HTTP Server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.trendmicro.com/en_us/research/22/b/recent-cyberattacks-open-source-web-servers.html
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2018-10-03·CVSS 5.9
CVE-2018-11763 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in the Apache HTTP Server.
Robert Swiecki discovered that the Apache HTTP Server HTTP/2 module
incorrectly destroyed certain streams. A remote attacker could possibly
use this issue to cause the server to crash, leading to a denial of
service. (CVE-2018-1302)
Craig Young discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain requests. A remote attacker could possibly
use this issue to cause the server to consume resources, leading to a
denial of service. (CVE-2018-1333)
Gal Goldshtein discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled large SETTINGS frames. A remote attacker could possibly
use this issue to cause the server to consume resources, leading
Red Hat
httpd: DoS for HTTP/2 connections by continuous SETTINGS frames
vendor_redhat·2018-09-25·CVSS 5.9
CVE-2018-11763 [MEDIUM] CWE-20 httpd: DoS for HTTP/2 connections by continuous SETTINGS frames
httpd: DoS for HTTP/2 connections by continuous SETTINGS frames
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: httpd (Red Hat Enterprise Linux 8) - Not affected
Package: mod_http2 (Red Hat Enterprise Linux 8) - Not affected
Package: httpd (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: httpd (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: httpd (Red Hat JBoss Enterpris
Debian
CVE-2018-11763: apache2 - In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS fr...
vendor_debian·2018·CVSS 5.9
CVE-2018-11763 [MEDIUM] CVE-2018-11763: apache2 - In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS fr...
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Scope: local
bookworm: resolved (fixed in 2.4.35-1)
bullseye: resolved (fixed in 2.4.35-1)
forky: resolved (fixed in 2.4.35-1)
sid: resolved (fixed in 2.4.35-1)
trixie: resolved (fixed in 2.4.35-1)
Apache
Apache httpd: CVE-2018-11763
vendor_apache·CVSS 5.9
CVE-2018-11763 [LOW] Apache httpd: CVE-2018-11763
Apache httpd: CVE-2018-11763
By sending continous SETTINGS frames of maximum size an ongoing HTTP/2 connection could be kept busy and would never time out. This can be abused for a DoS on the server. This only affect a server that has enabled the h2 protocol. Acknowledgements: The issue was discovered by Gal Goldshtein of F5 Networks. Reported to security team 2018-07-18 Issue public 2018-09-25 Update 2.4.35 released 2018-09-29 Affects 2.4.34, 2.4.33, 2.4.30, 2.4.29, 2.4.28, 2.4.27, 2.4.26, 2.4.25, 2.4.23, 2.4.20, 2.4.18
Severity: low
No detection rules found.
No public exploits indexed.
Trendmicro
Cyberangriffe auf Open Source-Webserver
blogs_trendmicro·2022-03-03·CVSS 9.8
[CRITICAL] Cyberangriffe auf Open Source-Webserver
APT und gezielte Angriffe
## Cyberangriffe auf Open Source-Webserver
Cyberangriffe auf Open-Source-Webserver wie Apache HTTP Server haben rapide zugenommen. Angriffe wie die Ausführung von Remote-Code, die Umgehung von Zugriffskontrollen, Denial-of-Service oder Cyberjacking dienen dem Mining von Kryptowährungen.
By: Jon Clay Mar 03, 2022 Read time: ( words)
Save to Folio
Originalartikel von Jon Clay, VP, Threat Intelligence
Cyberangriffe auf Open-Source-Webserver wie Apache HTTP Server haben rapide zugenommen. Böswillige Akteure setzen dabei auf Angriffe wie Remote Code Execution (RCE), Umgehung der Zugriffskontrolle, Denial of Service (DoS) oder sogar Cyberjacking, um auf den Servern der Opfer Kryptowährungen zu schürfen. Um Unternehmen vor bösartigen Aktivitäten zu schützen, bedarf
Trendmicro
Recent Cyberattacks Increasingly Target Open-source Web Servers
blogs_trendmicro·2022-02-22·CVSS 9.8
CVE-2021-44228 [CRITICAL] Recent Cyberattacks Increasingly Target Open-source Web Servers
APT & Targeted Attacks
# Recent Cyberattacks Target Open-source Web Servers
Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution, access control bypass, denial of service, or even cyberjacking the victim servers to mine cryptocurrencies.
By: Jon Clay
2022/02/22
Read time: ( words)
Save to Folio
As organizations reeled from the Log4Shell vulnerability (CVE-2021-44228), cyberattacks aiming at open-source web servers, like Apache HTTP Server, were rapidly rising. Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution (RCE), access control bypass, denial of service (DoS), or even cyberjacking the victim servers to mine cryptocurrencies.
To protect enterprises against m
Bugzilla
CVE-2018-11763 mod_http2: httpd: DoS for HTTP/2 connections by continuous SETTINGS frames [fedora-all]
bugzilla·2018-09-26·CVSS 5.9
CVE-2018-11763 [MEDIUM] CVE-2018-11763 mod_http2: httpd: DoS for HTTP/2 connections by continuous SETTINGS frames [fedora-all]
CVE-2018-11763 mod_http2: httpd: DoS for HTTP/2 connections by continuous SETTINGS frames [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2018-11763 httpd: DoS for HTTP/2 connections by continuous SETTINGS frames
bugzilla·2018-09-26·CVSS 5.9
CVE-2018-11763 [MEDIUM] CVE-2018-11763 httpd: DoS for HTTP/2 connections by continuous SETTINGS frames
CVE-2018-11763 httpd: DoS for HTTP/2 connections by continuous SETTINGS frames
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
References:
https://httpd.apache.org/security/vulnerabilities_24.html
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 1633400]
---
The httpd packages in Red Hat Enterprise Linux 7 and earlier do not include support for HTTP/2 and hence are not affected by this issue.
---
This issue is fixed upstream in httpd in the following commits:
trunk: https://svn.apache.org/r1840010
2.4.x: https:
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.htmlhttp://www.securityfocus.com/bid/105414http://www.securitytracker.com/id/1041713https://access.redhat.com/errata/RHSA-2018:3558https://access.redhat.com/errata/RHSA-2019:0366https://access.redhat.com/errata/RHSA-2019:0367https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190204-0004/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_ushttps://usn.ubuntu.com/3783-1/https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.tenable.com/security/tns-2019-09http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.htmlhttp://www.securityfocus.com/bid/105414http://www.securitytracker.com/id/1041713https://access.redhat.com/errata/RHSA-2018:3558https://access.redhat.com/errata/RHSA-2019:0366https://access.redhat.com/errata/RHSA-2019:0367https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190204-0004/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_ushttps://usn.ubuntu.com/3783-1/https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.tenable.com/security/tns-2019-09
2018-09-25
Published
Exploited in the wild