Description
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0124)
Twisted Web HTTP Server Improper Certificate Validation Vulnerability (CVE-2014-7143)
TYPO3 Other Vulnerability (CVE-2007-1081)
WordPress Plugin Subscribe to Comments Unsubscribe Challenge Information Disclosure (2.0.2)