Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 27, 2017 |
| Amazon_linux | — | Upgrade httpdUpgrade httpd24 | Jan 20, 2017 | Dec 20, 2016 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 27, 2017 | Jul 27, 2017 |
| Apple Osx Apache | — | Apply OS X security update 2017-001 SierraUpgrade macOS to the latest versionApply OS X security update 2017-004 El Capitan | Mar 28, 2017 | Mar 28, 2017 |
| Centos_linux | — | Upgrade httpdUpgrade httpd-develUpgrade httpd-toolsUpgrade httpd-debuginfoUpgrade mod_sslUpgrade mod_ldapUpgrade mod_sessionUpgrade httpd-manualUpgrade mod_proxy_html | Apr 13, 2017 | Dec 20, 2016 |
| Debian | — | Upgrade apache2 | Feb 27, 2017 | Dec 20, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 3, 2017 |
| Freebsd | — | Upgrade apache24 | Dec 21, 2016 | Dec 21, 2016 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jul 27, 2017 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Apr 7, 2018 | Dec 20, 2016 |
| Hpux | — | Update hpuxws24APACHE.AUTH_LDAP2 to the latest versionUpdate hpuxws24APACHE.MOD_JK to the latest versionUpdate hpuxws24APACHE.AUTH_LDAP to the latest versionUpdate hpuxws24APACHE.WEBPROXY to the latest versionUpdate hpuxws24APACHE.APACHE to the latest versionUpdate hpuxws24APACHE.APACHE2 to the latest versionUpdate hpuxws24APACHE.MOD_JK2 to the latest versionUpdate hpuxws24APACHE.MOD_PERL to the latest versionUpdate hpuxws24APACHE.WEBPROXY2 to the latest versionUpdate hpuxws24APACHE.MOD_PERL2 to the latest version | Aug 11, 2017 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade httpd-manualUpgrade mod_sslUpgrade httpdUpgrade httpd-develUpgrade httpd-tools | Jan 18, 2018 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade httpd-develUpgrade mod_sslUpgrade httpd-toolsUpgrade httpd-manualUpgrade httpd | Jan 18, 2018 | Jul 27, 2017 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.5.5.12 or laterApply IBM HTTP Server version 7.0.0.43 or laterApply IBM HTTP Server version 9.0.0.3 or laterApply IBM HTTP Server Interim Fix PI73984Apply IBM HTTP Server version 8.0.0.14 or later | Sep 7, 2022 | Sep 7, 2022 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-dbd to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-lua to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-22/documentation to version 2.2.32-0.175.3.18.0.4.0 on Solaris 11.3Upgrade web/server/apache-22 to version 2.2.32-0.175.3.18.0.4.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-22/module/apache-sed to version 2.2.32-0.175.3.18.0.4.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-gss to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Oracle_linux | — | Upgrade httpd-develUpgrade mod_proxy_htmlUpgrade httpdUpgrade httpd-toolsUpgrade mod_sslUpgrade httpd-manualUpgrade mod_ldapUpgrade mod_session | Apr 13, 2017 | Dec 20, 2016 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Dec 20, 2016 |
| Redhat_linux | — | No solution existsUpgrade mod_sessionUpgrade httpd-debuginfoUpgrade httpdUpgrade mod_ldapUpgrade mod_sslUpgrade httpd-develUpgrade mod_proxy_htmlUpgrade httpd-toolsUpgrade httpd-manual | Apr 12, 2017 | Dec 20, 2016 |
| Suse | — | Upgrade apache2-develUpgrade apache2-docUpgrade apache2-preforkUpgrade apache2-example-pagesUpgrade apache2-utilsUpgrade apache2-eventUpgrade apache2Upgrade apache2-worker | Mar 18, 2017 | Dec 20, 2016 |
| Ubuntu | — | Upgrade apache2-binUpgrade apache2.2-bin | May 9, 2017 | Dec 20, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub