Vulnerabilities > CVE-2021-33193

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE

Summary

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.

Vulnerable Configurations

Part Description Count
OS
Debian
1
OS
Fedoraproject
2
Application
Apache
32
Application
Tenable
9
Application
Oracle
11

References