Apache HTTP Server mod_ssl Log Injection Vulnerability

Vulnerability

A log injection vulnerability has been identified in the mod_ssl module of Apache HTTP Server in versions through 2.4.63. This issue arises from inadequate escaping of user-supplied data, allowing untrusted SSL/TLS clients to insert escape characters into log files under certain configurations. Specifically, when CustomLog is used to log variables provided by mod_ssl, such as SSL_TLS_SNI, the lack of proper escaping can result in unsanitized client data appearing in the logs.

Impact

Exploitation of this vulnerability can lead to log injection, where maliciously crafted data from an untrusted SSL/TLS client is logged without proper sanitization, potentially causing misinterpretation of log data or interference with log processing.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.64 or later, which addresses this vulnerability.

Added: Jul 10, 2025, 5:42 PM
Updated: Jul 10, 2025, 5:42 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.0
exploitability
7.6
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.