PublicDateAtUSN: 2021-08-16 08:15:00 UTC Candidate: CVE-2021-33193 PublicDate: 2021-08-16 08:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33193 https://portswigger.net/research/http2 https://ubuntu.com/security/notices/USN-5090-1 Description: A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. Ubuntu-Description: Notes: mdeslaur> commits for trunk and 2.4 don't match, needs investigation mdeslaur> commit for 2.4 is the one listed in the vulnerability report mdeslaur> as of 2021-08-26, no new version of apache contains the fix Mitigation: Bugs: Priority: medium Discovered-by: James Kettle Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_apache2: upstream: https://github.com/apache/httpd/commit/f990e5ecad40b100a8a5c7c1033c46044a9cb244 (trunk) upstream: https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c (2.4) upstream_apache2: released (2.4.48-4) trusty_apache2: ignored (out of standard support) trusty/esm_apache2: not-affected (code not present) xenial_apache2: ignored (out of standard support) esm-infra/xenial_apache2: not-affected (http2 disabled in xenial) bionic_apache2: released (2.4.29-1ubuntu4.17) focal_apache2: released (2.4.41-4ubuntu3.5) hirsute_apache2: released (2.4.46-4ubuntu1.2) impish_apache2: released (2.4.48-3.1ubuntu2) jammy_apache2: released (2.4.48-3.1ubuntu2) devel_apache2: released (2.4.48-3.1ubuntu2)