REDHAT-BUG-1695042: Low severity Apache HTTP Server vulnerability
When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. A server that never enabled the h2 protocol or that only enabled it for https: and did not configure the "H2Upgrade on" is unaffected by this.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1695042?
The severity of REDHAT-BUG-1695042 is classified as low.
What is the risk associated with REDHAT-BUG-1695042?
REDHAT-BUG-1695042 has a risk rating of 5.
How do I fix REDHAT-BUG-1695042?
To fix REDHAT-BUG-1695042, ensure that HTTP/2 is only enabled for appropriate hosts and configurations.
What causes the vulnerability REDHAT-BUG-1695042?
REDHAT-BUG-1695042 is caused by an Upgrade request from HTTP/1.1 to HTTP/2 that is not the first request on a connection, leading to potential misconfiguration.
Which software is affected by REDHAT-BUG-1695042?
REDHAT-BUG-1695042 affects the Apache HTTP Server.