Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4ch-cv96-r58v

Опубликовано: 04 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.

Users are recommended to upgrade to version 2.4.59, which fixes this issue.

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.

Users are recommended to upgrade to version 2.4.59, which fixes this issue.

EPSS

Процентиль: 78%
0.01253
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-113
CWE-444

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 4
redhat
больше 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 6.3
nvd
больше 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS3: 6.3
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 6.3
debian
больше 1 года назад

HTTP Response splitting in multiple modules in Apache HTTP Server allo ...

EPSS

Процентиль: 78%
0.01253
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-113
CWE-444