HIGH · 7.5

CVE-2020-11993

Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing conc...

Vulnerability Description

Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheHttp Server>= 2.4.20, < 2.4.44
NetappClustered Data Ontap-
CanonicalUbuntu Linux16.04
OpensuseLeap15.1
DebianDebian Linux10.0
FedoraprojectFedora31
OracleCommunications Element Manager>= 8.2.0, <= 8.2.2
OracleCommunications Session Report Manager>= 8.2.0, <= 8.2.2
OracleCommunications Session Route Manager>= 8.2.0, <= 8.2.2
OracleEnterprise Manager Ops Center12.4.0.0
OracleHyperion Infrastructure Technology11.1.2.4
OracleInstantis Enterprisetrack17.1
OracleZfs Storage Appliance Kit8.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11993?

CVE-2020-11993 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing conc...

How severe is CVE-2020-11993?

CVE-2020-11993 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11993?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Netapp Clustered Data Ontap, Canonical Ubuntu Linux, Opensuse Leap, Debian Debian Linux.