Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- >= 2.4, <= 2.4.63
A log injection vulnerability has been identified in the mod_ssl module of Apache HTTP Server in versions through 2.4.63. This issue arises from inadequate escaping of user-supplied data, allowing untrusted SSL/TLS clients to insert escape characters into log files under certain configurations. Specifically, when CustomLog is used to log variables provided by mod_ssl, such as SSL_TLS_SNI, the lack of proper escaping can result in unsanitized client data appearing in the logs.
Exploitation of this vulnerability can lead to log injection, where maliciously crafted data from an untrusted SSL/TLS client is logged without proper sanitization, potentially causing misinterpretation of log data or interference with log processing.
Users are advised to upgrade to Apache HTTP Server version 2.4.64 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.