CVE-2023-27522

Updated: 2023-03-14 23:07:37.889175

Description:

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 8.4 ELS httpd 2.4.37 7.5 HIGH Released CLSA-2023:1679000716 2023-03-16 21:02:31
CentOS 8.5 ELS httpd 2.4.37 7.5 HIGH Released CLSA-2023:1679000442 2023-03-16 17:03:53
Ubuntu 16.04 ELS apache2 2.4.18 7.5 HIGH Ignored 2023-03-13 05:03:39
Ubuntu 18.04 ELS apache2 2.4.29 7.5 HIGH Needs Triage 2023-03-10 09:24:34

Statement

Will not fix: low score