Lucene search

K
f5F5F5:K000132965
HistoryMar 14, 2023 - 12:00 a.m.

K000132965 : Apache vulnerability CVE-2023-27522

2023-03-1400:00:00
my.f5.com
13
apache
http server
vulnerability
cve-2023-27522
mod_proxy_uwsgi
response smuggling
impact
attacker
message
software

AI Score

6.4

Confidence

Low

EPSS

0.014

Percentile

86.4%

Security Advisory Description

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. (CVE-2023-27522)

Impact

An attacker may be able to “smuggle” a message to the client/server without the intermediary being aware of it.