Rapid7 Vulnerability & Exploit Database

Oracle Linux: (CVE-2023-25690) (Multiple Advisories): httpd:2.4 security update

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Oracle Linux: (CVE-2023-25690) (Multiple Advisories): httpd:2.4 security update

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
03/07/2023
Created
05/05/2023
Added
04/05/2023
Modified
08/11/2023

Description

Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.

Configurations are affected when mod_proxy is enabled along with some form of RewriteRule

or ProxyPassMatch in which a non-specific pattern matches

some portion of the user-supplied request-target (URL) data and is then

re-inserted into the proxied request-target using variable

substitution. For example, something like:

RewriteEngine on

RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P]

ProxyPassReverse /here/ http://example.com:8080/

Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.

Solution(s)

  • oracle-linux-upgrade-httpd
  • oracle-linux-upgrade-httpd-core
  • oracle-linux-upgrade-httpd-devel
  • oracle-linux-upgrade-httpd-filesystem
  • oracle-linux-upgrade-httpd-manual
  • oracle-linux-upgrade-httpd-tools
  • oracle-linux-upgrade-mod_http2
  • oracle-linux-upgrade-mod_ldap
  • oracle-linux-upgrade-mod_lua
  • oracle-linux-upgrade-mod_md
  • oracle-linux-upgrade-mod_proxy_html
  • oracle-linux-upgrade-mod_session
  • oracle-linux-upgrade-mod_ssl

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;