Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-11763

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.192
EPSS Ranking 95.0%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
References
Products affected by CVE-2018-11763


Contact Us

Shodan ® - All rights reserved