REDHAT-BUG-2374578: Medium severity Apache HTTP Server vulnerability
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in modproxyhttp2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to \"on\"
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2374578?
The severity of REDHAT-BUG-2374578 is considered to be high due to the potential for denial of service attacks.
How do I fix REDHAT-BUG-2374578?
To fix REDHAT-BUG-2374578, update Apache HTTP Server to a version beyond 2.4.63 or ensure that the configuration does not allow untrusted clients.
What versions of Apache HTTP Server are affected by REDHAT-BUG-2374578?
Apache HTTP Server versions 2.4.26 through 2.4.63 are affected by REDHAT-BUG-2374578.
What configurations are vulnerable in REDHAT-BUG-2374578?
Redhat-BUG-2374578 affects configurations where a reverse proxy is set up for an HTTP/2 backend.
What type of attack does REDHAT-BUG-2374578 expose systems to?
REDHAT-BUG-2374578 exposes systems to denial of service attacks due to assertions triggered by untrusted clients.