HTTP Response Splitting Vulnerability in Apache HTTP Server
CVE-2024-42516
7.5HIGH
What is CVE-2024-42516?
A vulnerability in the core of Apache HTTP Server permits attackers to exploit HTTP response splitting by manipulating the Content-Type response headers. This flaw allows unauthorized parties to split a server's HTTP responses, potentially leading to various attacks, including cross-site scripting (XSS) or cache poisoning. Despite previous mentions of a related issue in CVE-2023-38709, the patch in Apache HTTP Server version 2.4.59 did not adequately resolve the exploit. Users are strongly advised to upgrade to version 2.4.64, which rectifies this vulnerability and enhances server security.
Affected Version(s)
Apache HTTP Server 2.4.0 <= 2.4.63