CVE-2020-11993: High severity Apache HTTP Server vulnerability
A flaw was found in Apache httpd in versions 2.4.20 to 2.4.43. Logging using the wrong pool by modhttp2 at debug/trace log level may lead to potential crashes and denial of service. The highest threat from this vulnerability is to system availability.
Other sources
A flaw was found in httpd before version 2.4.46. Logging using the wrong pool by modhttp2 at debug/trace log level may lead to potential crashes and denial of service.
Upstream patch:
https://github.com/icing/modh2/commit/89773a4f98ee9a9fb402470e04b6f4044faa7fdf
— Red Hat
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of modhttp2 above "info" will mitigate this vulnerability for unpatched servers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-104.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-75.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-38.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-44.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-64.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-53.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-34.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-32.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-104.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-75.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-38.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-44.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-64.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-53.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-34.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-32.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-chilto a version that resolves this vulnerability.Fixed in 0:1.0.0-1.jbcs.el7 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-22.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.44 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1 - Configuration
For unpatched Apache httpd, configure the LogLevel of mod_http2 to be at "info" or lower (mitigates when debug/trace is enabled for the HTTP/2 module).
Apache httpd (mod_http2) LogLevel = info (set to "info" or lower; do not set above "info")
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11993.
What is the severity of CVE-2020-11993?
The severity of CVE-2020-11993 is high.
Which versions of Apache HTTP Server are affected by CVE-2020-11993?
Apache HTTP Server versions 2.4.20 to 2.4.43 are affected by CVE-2020-11993.
How can I mitigate the vulnerability?
Configuring the LogLevel of mod_http2 above "info" will mitigate CVE-2020-11993.
Where can I find more information about CVE-2020-11993?
You can find more information about CVE-2020-11993 at the following references: [1] [2] [3]