Threat Encyclopedia

Security Vulnerability CVE-2020-9490 for Apache HTTP Server


Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the \'Cache-Digest\' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via \"H2Push off\" will mitigate this vulnerability for unpatched servers.

affected-products-logoAffected Products

Apache HTTP Server

CVE References