cbcvebase.
CVE-2024-24795
published 2024-04-04

CVE-2024-24795: HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to…

medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

Affected

21 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.0 < 2.4.592.4.59
apache_software_foundationapache_http_server2.4.0 – 2.4.58
applemacos< 14.614.6
applemacos_sonoma
debianapache2< apache2 2.4.59-1~deb12u1 (bookworm)apache2 2.4.59-1~deb12u1 (bookworm)
debiandebian_linux
debianuwsgi< apache2 2.4.59-1~deb12u1 (bookworm)apache2 2.4.59-1~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_httpd_2.4.58-4_on_azure_linux_3.0
msrcazl3_httpd_2.4.61-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_httpd_2.4.58-1_on_cbl_mariner_2.0
msrccbl2_httpd_2.4.59-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
netappontap
netappontap_tools
ubuntuapache2

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
osv7.3HIGH