Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Aug 15, 2018 | Aug 14, 2018 |
| Centos_linux | — | Upgrade mod_proxy_htmlUpgrade httpd-manualUpgrade mod_ldapUpgrade mod_sessionUpgrade mod_sslUpgrade httpdUpgrade httpd-develUpgrade httpd-toolsUpgrade httpd-debuginfo | Jan 22, 2020 | Aug 14, 2018 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Aug 14, 2018 |
| Hpux | — | Update hpuxwsAPACHE to the latest version | Mar 28, 2022 | Aug 14, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade httpd-develUpgrade mod_sslUpgrade httpd-toolsUpgrade httpd-manualUpgrade httpd | Dec 4, 2019 | Aug 14, 2018 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.0.3 or later | Aug 15, 2018 | Aug 14, 2018 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-lua to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-gss to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3 | Nov 23, 2018 | Aug 14, 2018 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Aug 14, 2018 |
| Redhat_linux | — | Upgrade mod_ldapUpgrade httpd-toolsUpgrade mod_sessionNo solution existsUpgrade mod_proxy_htmlUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-develUpgrade httpd-debuginfoUpgrade httpd | Jan 22, 2020 | Aug 14, 2018 |
| Suse | — | Upgrade apache2Upgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-example-pagesUpgrade apache2-develUpgrade apache2-docUpgrade apache2-utils | Aug 31, 2018 | Aug 14, 2018 |
| Ubuntu | — | Upgrade apache2 | Nov 19, 2024 | Aug 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub