7.3

CVE-2023-38709

Apache HTTP Server: HTTP response splitting

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.

This issue affects Apache HTTP Server: through 2.4.58.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ HTTP Server Version < 2.4.59
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 38
Fedoraproject ≫ Fedora Version 39
Fedoraproject ≫ Fedora Version 40
Netapp ≫ Ontap Version 9
Netapp ≫ Ontap Tools Version 10 SwPlatform vmware_vsphere
Apple ≫ macOS Version < 14.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.91% 0.889
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-1284 Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

https://httpd.apache.org/security/vulnerabilities_24.html
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2024/Jul/18
Third Party Advisory
Mailing List
https://support.apple.com/kb/HT214119
Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/04/04/3
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20240415-0013/
Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/07/10/2
http://www.openwall.com/lists/oss-security/2025/07/10/3