Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)

Disclosed: 2023-03-23 04:36:10 By nyxsorcerer To ibb
Medium
Vulnerability Details
#Summary HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2023-27522 ## Impact The response headers can be truncated, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
Actions
View on HackerOne
Report Stats
  • Report ID: 1910810
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report