HTTP Response Splitting Vulnerability in Apache HTTP Server
CVE-2024-42516
7.5HIGH
What is CVE-2024-42516?
A vulnerability in the core of Apache HTTP Server permits attackers to exploit HTTP response splitting by manipulating the Content-Type response headers. This flaw allows unauthorized parties to split a server's HTTP responses, potentially leading to various attacks, including cross-site scripting (XSS) or cache poisoning. Despite previous mentions of a related issue in CVE-2023-38709, the patch in Apache HTTP Server version 2.4.59 did not adequately resolve the exploit. Users are strongly advised to upgrade to version 2.4.64, which rectifies this vulnerability and enhances server security.
Affected Version(s)
Apache HTTP Server 2.4.0 <= 2.4.63
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved