Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache mod_proxy_ajp模块入站请求体远程拒绝服务漏洞
Vulnerability Description
Apache HTTP Server是一款流行的Web服务器。 Apache HTTP Server在处理某些畸形的入站消息时,Apache服务器mod_proxy_ajp模块的modules/proxy/mod_proxy_ajp.c文件中的ap_proxy_ajp_request()函数可能会返回HTTP_INTERNAL_SERVER_ERROR的出错代码。这可能导致后端服务器一直处于出错状态,直到重试超时过期。
CVSS Information
N/A
Vulnerability Type
N/A