SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1303

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory.

HIGH 7.5EPSS 69.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 69.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
69.80% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
apache/http server · debian/debian linux · canonical/ubuntu linux · netapp/santricity cloud connector · netapp/storage automation store · netapp/storagegrid · netapp/clustered data ontap
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.