PT-2023-2026 · Apache+10 · Apache Http Server+10

Lars Krapf

·

Published

2022-11-08

·

Updated

2026-03-10

·

CVE-2023-25690

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.55
Description The issue is related to HTTP Request Smuggling attacks, which can occur when mod proxy is enabled along with certain RewriteRule or ProxyPassMatch configurations. These configurations can allow an attacker to bypass access controls in the proxy server, proxy unintended URLs to existing origin servers, and perform cache poisoning. The vulnerability can be exploited when a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, a configuration like RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ can be vulnerable. Approximately 33,652,790 results are affected.
Recommendations Update to at least version 2.4.56 of Apache HTTP Server to resolve the issue. As a temporary workaround, consider disabling the mod proxy module or restricting the use of RewriteRule and ProxyPassMatch configurations until a patch is available. Avoid using vulnerable configurations, such as those that enable variable substitution in the proxied request-target.

Exploit

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

ALSA-2022_7647
ALSA-2022_8067
ALSA-2023:1670
ALSA-2023:1673
ALSA-2023_0852
ALSA-2023_0970
ALSA-2023_1670
ALSA-2023_1673
ALSA-2023_5050
ALSA-2023_6403
ALSA-2025_16880
ALT-PU-2023-1402
ALT-PU-2023-1437
ALT-PU-2023-1452
ALT-PU-2023-2055
AZL-25605
AZL-43903
AZL-45186
BDU:2023-01738
BIT-APACHE-2023-25690
CESA-2023_1673
CVE-2023-25690
DLA-3401-1
DSA-5376-1
ELSA-2023-1593
ELSA-2023-1670
ELSA-2023-1673
MGASA-2023-0100
OESA-2023-1161
OPENSUSE-SU-2024:12776-1
RHSA-2023:1547
RHSA-2023:1593
RHSA-2023:1596
RHSA-2023:1597
RHSA-2023:1670
RHSA-2023:1672
RHSA-2023:1673
RHSA-2023:1916
RHSA-2023:3292
RHSA-2023:3354
RHSA-2023_1593
RHSA-2023_1670
RHSA-2023_1673
RLSA-2023:1670
RLSA-2023:1673
RLSA-2023_1670
RLSA-2023_1673
ROSA-SA-2023-2158
SUSE-SU-2023:0764-1
SUSE-SU-2023:0799-1
SUSE-SU-2023:0803-1
SUSE-SU-2023:1573-1
SUSE-SU-2023:1658-1
SUSE-SU-2023_0764-1
SUSE-SU-2023_0799-1
SUSE-SU-2023_0803-1
SUSE-SU-2023_1573-1
SUSE-SU-2023_1658-1
USN-5942-1
USN-5942-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu