CVE-2024-36387NULL Pointer Dereference in Software Foundation Apache Http Server

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 59.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateJul 11

Description

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

NVDapache/http_server2.4.552.4.59

Also affects: Ontap 9

🔴Vulnerability Details

5
OSV
apache2 regression2024-07-11
OSV
apache2 vulnerabilities2024-07-08
GHSA
GHSA-463r-p989-2f9j: Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, deg2024-07-01
OSV
CVE-2024-36387: Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, deg2024-07-01
CVEList
Apache HTTP Server: DoS by Null pointer in websocket over HTTP/22024-07-01

📋Vendor Advisories

4
Microsoft
Apache HTTP Server: DoS by Null pointer in websocket over HTTP/22024-07-09
Ubuntu
Apache HTTP Server vulnerabilities2024-07-08
Red Hat
mod_http2: DoS by null pointer in websocket over HTTP/22024-07-01
Debian
CVE-2024-36387: apache2 - Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a N...2024
CVE-2024-36387 — NULL Pointer Dereference | cvebase