Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46346
HistoryApr 10, 2024 - 9:30 p.m.

HTTP Response Splitting

2024-04-1021:30:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
http response splitting
apache
backend injection
desynchronization attack

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%

Apache HTTP Server is vulnerable to HTTP Response splitting. The vulnerability is due to inadequate handling of malicious response headers, allowing an attacker to inject headers into backend applications and cause an HTTP desynchronization attack.