In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4270-1 | apache2 security update |
EUVD |
EUVD-2024-54773 | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files. |
Ubuntu USN |
USN-7639-1 | Apache HTTP Server vulnerabilities |
Ubuntu USN |
USN-7639-2 | Apache HTTP Server vulnerabilities |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 29 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache http Server
|
|
| CPEs | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache http Server
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Mon, 14 Jul 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Thu, 10 Jul 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files. | |
| Title | Apache HTTP Server: mod_ssl error log variable escaping | |
| Weaknesses | CWE-150 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:08:59.176Z
Reserved: 2024-09-23T15:25:33.808Z
Link: CVE-2024-47252
Updated: 2025-11-04T21:08:59.176Z
Status : Modified
Published: 2025-07-10T17:15:46.400
Modified: 2025-11-04T22:16:04.060
Link: CVE-2024-47252
OpenCVE Enrichment
Updated: 2025-07-12T22:09:39Z
Debian DLA
EUVD
Ubuntu USN