Description
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0996 | A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue. |
Ubuntu USN |
USN-4113-1 | Apache HTTP Server vulnerabilities |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apache
Subscribe
Http Server
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Oracle
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Enterprise Manager Ops Center
Subscribe
Http Server
Subscribe
Instantis Enterprisetrack
Subscribe
Retail Xstore Point Of Service
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T17:44:14.751Z
Reserved: 2018-11-14T00:00:00.000Z
Link: CVE-2019-0197
No data.
Status : Modified
Published: 2019-06-11T22:29:04.170
Modified: 2024-11-21T04:16:27.960
Link: CVE-2019-0197
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN