CVE-2023-27522

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:unbit:uwsgi:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-03-07 16:15

Updated : 2023-09-08 22:15


NVD link : CVE-2023-27522

Mitre link : CVE-2023-27522

CVE.ORG link : CVE-2023-27522


JSON object : View

Products Affected

apache

  • http_server

debian

  • debian_linux

unbit

  • uwsgi
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')