Lucene search

K
hackeroneOrangeH1:2585373
HistoryJul 03, 2024 - 6:52 a.m.

Internet Bug Bounty: moderate: Apache HTTP Server: HTTP response splitting (CVE-2023-38709)

2024-07-0306:52:53
orange
hackerone.com
$2600
23
internet bug bounty
http response splitting
apache http server
input validation
cve-2023-38709
security vulnerability

AI Score

6.9

Confidence

High

I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html

Impact

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.

This issue affects Apache HTTP Server: through 2.4.58.