Description
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2007-0287)
WordPress Plugin G Auto-Hyperlink SQL Injection (1.0.1)
Magento Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-9690)
WordPress Plugin ApplyOnline-Application Form Builder and Manager Arbitrary File Disclosure (1.9.92)