CVE-2023-27522: Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
HTTP Response Smuggling vulnerability in Apache HTTP Server via modproxyuwsgi. This issue affects Apache HTTP Server from 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22. Special characters in the origin response header can truncate/split the response forwarded to the client.
Other sources
HTTP Response Smuggling vulnerability in Apache HTTP Server via modproxyuwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.
Special characters in the origin response header can truncate/split the response forwarded to the client.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/uWSGIto a version that resolves this vulnerability.Fixed in 2.0.22 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.56 - Upgrade
Upgrade
Apache HTTP Server (mod_proxy_uwsgi)to a version that resolves this vulnerability.Fixed in 2.4.56
Event History
Frequently Asked Questions
What is CVE-2023-27522?
CVE-2023-27522 is an HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi.
Which software versions are affected by CVE-2023-27522?
Apache HTTP Server versions 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22 are affected.
How can CVE-2023-27522 be exploited?
By using special characters in the origin response header, an attacker can truncate/split the response forwarded to the client.
What is the severity of CVE-2023-27522?
CVE-2023-27522 has a severity rating of 7.5 (High).
Where can I find more information about CVE-2023-27522?
You can find more information about CVE-2023-27522 on the NIST NVD, Apache HTTP Server security vulnerabilities page, and the Debian LTS-Announce mailing list.