CVE-2023-38709

Public on 2024-04-04
Modified on 2024-04-06
Description
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.

This issue affects Apache HTTP Server: through 2.4.58.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 httpd No Fix Planned
Amazon Linux 2 - Core httpd 2024-04-24 ALAS2-2024-2532 Fixed
Amazon Linux 2023 httpd 2024-04-25 ALAS2023-2024-607 Fixed
Amazon Linux 1 httpd24 No Fix Planned

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
NVD CVSSv3 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L