Special characters in the origin response header can truncate/split the response forwarded to the client.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3401-1 | apache2 security update |
Debian DSA |
DSA-5376-1 | apache2 security update |
EUVD |
EUVD-2023-1108 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. |
Github GHSA |
GHSA-vcph-37mh-fqrh | Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling |
Ubuntu USN |
USN-5942-1 | Apache HTTP Server vulnerabilities |
Thu, 13 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. |
Wed, 23 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:45:26.302Z
Reserved: 2023-03-02T12:24:47.536Z
Link: CVE-2023-27522
Updated: 2024-08-02T12:16:35.628Z
Status : Analyzed
Published: 2023-03-07T16:15:09.613
Modified: 2025-05-01T15:34:19.177
Link: CVE-2023-27522
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN