PT-2023-9026 · Apache+11 · Apache Http Server+11
Yeto
·
Published
2023-09-06
·
Updated
2026-05-28
·
CVE-2024-24795
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions prior to 2.4.59
Description
The issue is related to HTTP Response splitting in multiple modules in Apache HTTP Server, which allows an attacker to inject malicious response headers into backend applications, causing an HTTP desynchronization attack. This can be exploited by a remote attacker.
Recommendations
To resolve the issue, upgrade to version 2.4.59, which fixes this issue. As a temporary workaround, consider restricting access to vulnerable modules to minimize the risk of exploitation.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Debian
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu