Severity
7.5HIGH
EPSS
76.3%
top 1.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateMay 24

Description

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages13 packages

NVDapache/http_server2.4.202.4.46
CVEListV5apache_http_server2.4.20 to 2.4.43
Debianapache2< 2.4.46-1+3

Also affects: Debian Linux 10.0, Fedora 31, 32, Ubuntu Linux 16.04, 18.04, 20.04, Enterprise Linux 8.0, 8.1, 8.2, 8.4, 8.6

Patches

🔴Vulnerability Details

4
GHSA
GHSA-f2jx-wr3j-25w5: Apache HTTP Server versions 22022-05-24
OSV
apache2 vulnerabilities2020-08-13
OSV
CVE-2020-9490: Apache HTTP Server versions 22020-08-07
CVEList
CVE-2020-9490: Apache HTTP Server versions 22020-08-07

🔍Detection Rules

1
Suricata
ET EXPLOIT Apache2 Memory Corruption Inbound (CVE-2020-9490)2020-09-03

📋Vendor Advisories

4
Ubuntu
Apache HTTP Server vulnerabilities2020-08-13
Microsoft
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resour2020-08-11
Red Hat
httpd: Push diary crash on specifically crafted HTTP/2 header2020-08-07
Debian
CVE-2020-9490: apache2 - Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the ...2020

💬Community

2
Bugzilla
CVE-2020-9490 mod_http2: Push diary crash on specifically crafted HTTP/2 header [fedora-all]2020-08-11
Bugzilla
CVE-2020-9490 httpd: Push diary crash on specifically crafted HTTP/2 header2020-08-05