Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcph-37mh-fqrh

Опубликовано: 07 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server from 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22. Special characters in the origin response header can truncate/split the response forwarded to the client.

Пакеты

Наименование

uWSGI

pip
Затронутые версииВерсия исправления

< 2.0.22

2.0.22

EPSS

Процентиль: 71%
0.00695
Низкий

7.5 High

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.

CVSS3: 7.5
redhat
больше 2 лет назад

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.

CVSS3: 7.5
nvd
больше 2 лет назад

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_pr ...

EPSS

Процентиль: 71%
0.00695
Низкий

7.5 High

CVSS3

Дефекты

CWE-444