CVE-2018-17189
Severity
5.3MEDIUM
EPSS
5.6%
top 9.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 13
Description
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4
Affected Packages9 packages
Also affects: Debian Linux 9.0, Fedora 28, 29, Ubuntu Linux 14.04, 16.04, 18.04, 18.10