Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client. References: https://httpd.apache.org/security/vulnerabilities_24.html https://www.openwall.com/lists/oss-security/2023/01/17/7
Created httpd tracking bugs for this issue: Affects: fedora-all [bug 2162094]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:0852 https://access.redhat.com/errata/RHSA-2023:0852
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:0970 https://access.redhat.com/errata/RHSA-2023:0970
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-37436
This issue has been addressed in the following products: Red Hat JBoss Core Services Via RHSA-2023:4628 https://access.redhat.com/errata/RHSA-2023:4628
This issue has been addressed in the following products: JBoss Core Services on RHEL 7 JBoss Core Services for RHEL 8 Via RHSA-2023:4629 https://access.redhat.com/errata/RHSA-2023:4629