Apache HTTP Server versions 2.4.20 to 2.4.43 When trace...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 1, 2025
Description
Published by the National Vulnerability Database
Aug 7, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
May 1, 2025
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
References