CVE-2011-3348

Description

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary error state in the backend server) via a malformed HTTP request.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
37.038

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.20Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 4.3Windows
Update Apache to version 2.2.20 (For Linux)Linux
Uncontrolled Resource Consumption Vulnerability (CVE-2011-3348)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234