Apache httpd mod_proxy Null Pointer Dereference DoS

Strike ID:
E22-cnhc4
CVSS:
8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
False Positive:
f
Variants:
1
Year:
2021

Description

A denial of service vulnerability exists in multiple versions of Apache Software Foundation httpd prior to 2.4.52. The flaw is due to improper handling of malformed Request-URIs requests. An unauthenticated remote attacker may send a crafted request to the target server. Successful exploitation could result in a denial of service (DoS) condition.

CVE

References