Bug 2273499 (CVE-2024-24795)
| Summary: | CVE-2024-24795 httpd: HTTP Response Splitting in multiple modules | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | anjoseph, aruklets, asoldano, bbaranow, bdettelb, ben.argyle, bmaxwell, brian.stansberry, caswilli, chazlett, csutherl, darran.lofthouse, dfreiber, dkreling, doconnor, dosoudil, eglynn, hhorak, istudens, ivassile, iweiss, jburrell, jclere, jjoyce, jmai, jorton, jprabhak, jpretori, jschluet, kaycoth, lhh, lsvaty, luhliari, mark.r.caron, mburns, mgarciac, mosmerov, msochure, mstefank, msvehla, nbhumkar, nwallace, pesilva, pgrist, pjindal, plodge, pmackay, rhayakaw, rhel-process-autobot, rogbas, rstancel, smaestri, szappis, teagle, tom.jenkinson, tosorio, vchlup, vkumar, watson-tool-maintainers, wtam |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | httpd 2.4.59 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in httpd. An HTTP response splitting in multiple httpd modules may allow an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2273500, 2273505, 2273506, 2273507, 2273509 | ||
| Bug Blocks: | 2273504 | ||
|
Description
Pedro Sampaio
2024-04-04 19:04:16 UTC
Created httpd tracking bugs for this issue: Affects: fedora-all [bug 2273500] As I am unable to view any of 2273504, 2273506, 2273507, 2273505, or 2273509, can someone please tell me what the potential ETA is for this vulnerability being patched, please? This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9306 https://access.redhat.com/errata/RHSA-2024:9306 This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62 Via RHSA-2025:3453 https://access.redhat.com/errata/RHSA-2025:3453 This issue has been addressed in the following products: JBoss Core Services on RHEL 7 JBoss Core Services for RHEL 8 Via RHSA-2025:3452 https://access.redhat.com/errata/RHSA-2025:3452 |