SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1302

The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

MEDIUM 5.9EPSS 12.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 12.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
12.94% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
apache/http server · canonical/ubuntu linux · netapp/clustered data ontap · netapp/santricity cloud connector · netapp/storage automation store · netapp/storagegrid
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.