CERT-In Vulnerability Note
CIVN-2023-0079
Multiple Vulnerabilities in Apache HTTP Server
Original Issue Date:March 15, 2023
Severity Rating: HIGH
Software Affected
- Apache HTTP Server versions 2.4.0 through 2.4.55
Overview
Multiple vulnerabilities have been reported in Apache HTTP Server which could be exploited by an attacker to cause cache poisoning attacks on the targeted system.
Description
1. HTTP request smuggling vulnerability
(
CVE-2023-25690
)
A vulnerability exists in Apache HTTP Server when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch wherein non-specific pattern is matched with user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. A remote attacker could exploit the vulnerability by bypassing access controls in the proxy server causing Request splitting/smuggling attack. Successful exploitation of this vulnerability could allow remote attacker to cause cache poisoning attack on the targeted system.
2. HTTP response smuggling vulnerability
(
CVE-2023-27522
)
A vulnerability exists in Apache HTTP Server due to improper processing of character sequences in mod_proxy_uwsgi. A remote attacker could exploit the vulnerability by sending specially crafted request to the application to send a split HTTP response. Successful exploitation of this vulnerability could allow remote attacker to cause cache poisoning attack on the targeted system.
Solution
Apply appropriate fix/patches as mentioned in the following link
https://httpd.apache.org/security/vulnerabilities_24.html
Vendor Information
Apache
https://httpd.apache.org/security/vulnerabilities_24.html
References
Apache
https://httpd.apache.org/security/vulnerabilities_24.html
CVE Name
CVE-2023-25690
CVE-2023-27522
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|