Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-24795

Published: April 5, 2024Last modified: April 15, 2024

Description

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

Severity score breakdown

ParameterValue
Base score6.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSapache2Fixed (2.4.59-r0)
Streamapache2Fixed (2.4.59-r0)

References

ON THIS PAGE