Apache HTTP Server CVE-2020-9490 HTTP Request Smuggling Vulnerability

description-logoDescription

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the \'Cache-Digest\' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via \"H2Push off\" will mitigate this vulnerability for unpatched servers.

affected-products-logoAffected Applications

Apache HTTP Server

CVE References

CVE-2020-9490