Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-25690
Description:Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.
Test IDs: 1.3.6.1.4.1.25623.1.0.104597   1.3.6.1.4.1.25623.1.0.104598   1.3.6.1.4.1.25623.1.1.1.2.2023.3401   1.3.6.1.4.1.25623.1.1.4.2023.0803.1   1.3.6.1.4.1.25623.1.1.12.2023.5942.2  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-25690
https://security.gentoo.org/glsa/202309-01
http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html
https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/security/vulnerabilities_24.html
https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html




© 1998-2025 E-Soft Inc. All rights reserved.