Apache httpd是美国阿帕奇(Apache)基金会的一款专为现代操作系统开发和维护的开源HTTP服务器。 Apache httpd 存在资源管理错误漏洞,该漏洞源于允许客户端不停发送 HTTP/2 标头,导致内存耗尽。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | 2.4.17 ~ 2.4.58 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of concept (PoC) for CVE-2024-27316 (tested), CVE-2024-30255 (untested), CVE-2024-31309 (untested), CVE-2024-28182 (untested), CVE-2024-2653 (untested) and CVE-2024-27919 (untested) | https://github.com/lockness-Ko/CVE-2024-27316 | POC Details |
| 2 | None | https://github.com/aeyesec/CVE-2024-27316_poc | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-29006 | Apache CloudStack: x-forwarded-for HTTP header parsed by default | |
| CVE-2024-29007 | Apache CloudStack: When downloading templates or ISOs, the management server and SSVM foll | |
| CVE-2024-29008 | Apache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a | |
| CVE-2023-38709 | Apache HTTP Server: HTTP response splitting | |
| CVE-2024-24795 | Apache HTTP Server: HTTP Response Splitting in multiple modules |
No comments yet