The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
{
"cpe": [
"cpe:2.3:a:apache:http_server:2.4.17:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.17"
},
{
"last_affected": "2.4.18"
}
],
"source": "CPE_FIELD"
}