CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It affects Apache. Its EPSS score suggests a 20.1% probability of exploitation in the next 30 days.
CVE
CVE-2018-17189
Severity
MEDIUM
CVSS
5.3
EPSS
20.07%
Apache
Original NVD Description
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
Related CVEs
Other vulnerabilities affecting the same vendor(s)