A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
Configuration 5 (hide)
| 
 | 
History
                    01 May 2025, 15:40
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Debian debian Linux Debian | |
| CPE | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | |
| References | () https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patch - Patch | |
| References | () https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d%40%3Ccvs.httpd.apache.org%3E - Patch | |
| References | () https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70%40%3Ccvs.httpd.apache.org%3E - Patch | |
| References | () https://lists.debian.org/debian-lts-announce/2023/03/msg00002.html - Mailing List, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T/ - Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG/ - Third Party Advisory | 
Information
                Published : 2021-08-16 08:15
Updated : 2025-05-01 15:40
NVD link : CVE-2021-33193
Mitre link : CVE-2021-33193
CVE.ORG link : CVE-2021-33193
JSON object : View
Products Affected
                apache
- http_server
oracle
- zfs_storage_appliance_kit
- secure_backup
fedoraproject
- fedora
tenable
- tenable.sc
debian
- debian_linux
CWE
                