CVE-2024-42516: Apache HTTP Server: HTTP response splitting
CVE-2024-42516 - this is the "complete" fix for the CVE-2023-38709 response splitting issue. The patch issued upstream for CVE-2023-38709 did not fix the vulnerability.
Other sources
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 21.0.0.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.1.417.1.3.1 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u1Fixed in 2.4.67-1~deb12u2Fixed in 2.4.67-1~deb13u2Fixed in 2.4.67-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.64Patch CVE-2024-42516
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42516?
The severity of CVE-2024-42516 is high due to its potential to allow HTTP response splitting, which can lead to various attacks including web cache poisoning.
How do I fix CVE-2024-42516?
To fix CVE-2024-42516, upgrade your Apache HTTP Server to version 2.4.60 or later where the vulnerability is patched.
Who is affected by CVE-2024-42516?
CVE-2024-42516 affects users of Apache HTTP Server versions prior to 2.4.60 that utilize Content-Type response headers.
What are the potential exploits of CVE-2024-42516?
Potential exploits of CVE-2024-42516 include HTTP response splitting attacks which can lead to cross-site scripting, web cache poisoning, or user redirection.
Is CVE-2024-42516 still being actively exploited?
As of now, there have been reports indicating active exploitation of CVE-2024-42516, making it critical for affected users to apply patches immediately.