cbcvebase.
CVE-2018-1333
published 2018-06-18

CVE-2018-1333: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

Affected

14 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server2.4.18 – 2.4.30
apache_software_foundationapache_http_server
canonicalubuntu_linux
debianapache2< apache2 2.4.34-1 (bookworm)apache2 2.4.34-1 (bookworm)
highchartshighcharts>= 0 < 6.1.06.1.0
marked_projectmarked>= 0 < 0.3.170.3.17
mel-spintax_projectmel-spintax>= 0 < 1.0.31.0.3
protobufjs_projectprotobufjs>= 0 < 5.0.35.0.3
protobufjs_projectprotobufjs>= 6.0.0 < 6.8.66.8.6
redhatjboss_core_services
rgb2hex_projectrgb2hex>= 0 < 0.1.60.1.6
segmentiois-url>= 0 < 1.2.31.2.3
skeemas_projectskeemas>= 0 < 1.2.51.2.5

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH