Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- >= 2.4.0, <= 2.4.63
A moderate severity HTTP response splitting vulnerability has been identified in Apache HTTP Server versions 2.4.0 prior to 2.4.63. This vulnerability allows an attacker to manipulate the Content-Type response headers of applications hosted or proxied by the server, creating a split in the HTTP response. The issue arises from improper input validation, which can be exploited by malicious backend generators or content.
Exploitation of this vulnerability can lead to HTTP response splitting, allowing for HTTP desynchronization attacks. This could be used to bypass security controls, such as authentication or access restrictions, and potentially poison caches in proxying scenarios.
Users are advised to upgrade to Apache HTTP Server version 2.4.64, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.