Apache · Apache Http Server · CVE-2024-24795
**Name of the Vulnerable Software and Affected Versions**
Apache HTTP Server versions prior to 2.4.59
**Description**
The issue is related to HTTP Response splitting in multiple modules in Apache HTTP Server, which allows an attacker to inject malicious response headers into backend applications, causing an HTTP desynchronization attack. This can be exploited by a remote attacker.
**Recommendations**
To resolve the issue, upgrade to version 2.4.59, which fixes this issue. As a temporary workaround, consider restricting access to vulnerable modules to minimize the risk of exploitation.