CVE-2023-27522

CVSS V2 None CVSS V3 None
Description
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
Overview
  • CVE ID
  • CVE-2023-27522
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-03-07T16:15:09
  • Last Modified Date
  • 2023-04-25T00:15:10
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* 1 OR 2.4.30 2.4.55
History
Created Old Value New Value Data Type Notes
2023-04-17 06:02:44 Added to TrackCVE
2023-04-17 06:02:46 Weakness Enumeration new
2023-04-25 01:02:10 2023-04-25T00:15:10 CVE Modified Date updated
2023-04-25 01:02:10 Analyzed Modified Vulnerability Status updated
2023-04-25 01:02:11 HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. Description updated
2023-04-25 01:02:15 References updated