CVE-2020-9490

Click the icon to Follow me:- twitterTelegramRedditDiscord

Summary:

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the ‘Cache-Digest’ header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via “H2Push off” will mitigate this vulnerability for unpatched servers.

Reference Links(if available):

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-9490
  • https://security.gentoo.org/glsa/202008-04
  • https://lists.apache.org/thread.html/[email protected]%3Cdev.httpd.apache.org%3E
  • https://lists.apache.org/thread.html/[email protected]%3Cdev.httpd.apache.org%3E
  • https://lists.apache.org/thread.html/[email protected]%3Cdev.httpd.apache.org%3E
  • CVSS Score (if available)

    v2: / MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P

    v3: / HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    Links to Exploits(if available)

  • Available for Amazon Prime