Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4ch-cv96-r58v

Опубликовано: 04 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.

Users are recommended to upgrade to version 2.4.59, which fixes this issue.

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.

Users are recommended to upgrade to version 2.4.59, which fixes this issue.

EPSS

Процентиль: 47%
0.00238
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-113
CWE-444

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 4
redhat
около 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 6.3
nvd
около 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 6.3
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 6.3
debian
около 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allo ...

EPSS

Процентиль: 47%
0.00238
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-113
CWE-444