CVE-2020-13950 vulnerability in Apache and Other Products
Published on June 10, 2021
mod_proxy_http NULL pointer dereference
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service
Products Associated with CVE-2020-13950
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-13950 are published in these products:
Affected Versions
Apache Software Foundation Apache HTTP Server:- Version 2.4.46 is affected.
- Version 2.4.43 is affected.
- Version 2.4.41 is affected.
Exploit Probability
EPSS
19.46%
Percentile
95.26%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.