Lucene search

K
f5F5F5:K00373024
HistoryFeb 03, 2017 - 11:10 p.m.

Apache vulnerability CVE-2016-8743

2017-02-0323:10:00
support.f5.com
36

0.003 Low

EPSS

Percentile

68.0%

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution. (CVE-2016-8743)

Impact

An attacker may be able to perform HTTP request smuggling through specially crafted HTTP requests. For more information about HTTP request smuggling, refer to Section 9.5 Request Smuggling of Internet Engineering Task Force (RFC 7230).

Note: This link takes you to a resource outside of AskF5. The third party could remove the document without our knowledge.