Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Aug 15, 2018 | Aug 14, 2018 |
| Centos_linux | — | Upgrade httpd-manualUpgrade mod_sslUpgrade mod_proxy_htmlUpgrade mod_ldapUpgrade mod_sessionUpgrade httpd-develUpgrade httpdUpgrade httpd-debuginfoUpgrade httpd-tools | Jan 22, 2020 | Aug 14, 2018 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Aug 14, 2018 |
| Hpux | — | Update hpuxwsAPACHE to the latest version | Mar 28, 2022 | Aug 14, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade httpdUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-develUpgrade httpd-tools | Dec 4, 2019 | Aug 14, 2018 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.0.3 or later | Aug 15, 2018 | Aug 14, 2018 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-lua to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-gss to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3 | Nov 23, 2018 | Aug 14, 2018 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Aug 14, 2018 |
| Redhat_linux | — | Upgrade mod_sslUpgrade mod_proxy_htmlUpgrade httpd-develUpgrade httpd-manualUpgrade httpd-debuginfoNo solution existsUpgrade httpdUpgrade httpd-toolsUpgrade mod_ldapUpgrade mod_session | Jan 22, 2020 | Aug 14, 2018 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-example-pagesUpgrade apache2Upgrade apache2-utilsUpgrade apache2-develUpgrade apache2-doc | Aug 31, 2018 | Aug 14, 2018 |
| Ubuntu | — | Upgrade apache2 | Nov 19, 2024 | Aug 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub