Apache Security Update – 07 April 2024

Apache has released a security update to address a vulnerability in multiple versions of Apache HTTP Server.

The addressed vulnerability could allow the remote attacker to cause an out-ofmemory (OOM) crash and perform denial of service attacks on the affected system by sending a stream of continuation frames that will not be appended to the header list in memory but will still be processed and decoded by the server.

Apache HTTP Server Denial of Service Vulnerability (CVE-2024-27316):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

Affected versions:

  • Apache HTTP Server versions <= 2.4.58.
Vulnerabilities

CVE-2024-27316

Mitigations

The enterprise should deploy the patches as soon as the testing phase is completed.

Apache Security Update

References