top | item 28082212

(no title)

d_meeze | 4 years ago

Burying the lede... Unfortunately, at the time of this whitepaper being published - 86 days after Apache was notified of the vulnerability - 2.4.49 not yet come out, so although there's a patch on master, this is effectively a zero-day.

discuss

order

slivanes|4 years ago

I'm not seeing anything about this in nginx changelogs (or matching CVE's) either. Disabling http2 for now.

yxhuvud|4 years ago

Why would an Apache bug show up in Nginx changelogs?