CVE-2023-27522

Name
CVE-2023-27522
Description
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://httpd.apache.org/security/vulnerabilities_24.html
MISC https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html
MISC https://security.gentoo.org/glsa/202309-01

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* http_server >= 2.4.30 <= 2.4.55
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* http_server >= 2.4.30 < 2.4.56

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
apache2 3.14-main 2.4.56-r0 Kaarle Ritvanen <kaarle.ritvanen@datakunkku.fi> fixed