imPC@ndo IT

Tracker / CVE-2023-27522

CVE-2023-27522

High 7.5

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.

Affected products and versions

apache http_server · 2.4.30 → 2.4.56
debian debian_linux
unbit uwsgi · … → 2.0.22

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References