F5-K000153074: XSS
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000153074?
The severity of F5-K000153074 is considered critical due to the potential for HTTP response splitting attacks.
How do I fix F5-K000153074?
To fix F5-K000153074, ensure that you update to the latest patched version of the affected F5 products.
What versions are affected by F5-K000153074?
F5-K000153074 affects specific versions of F5 BIG-IP, F5OS-A, F5OS-C, and Traffix SDC.
What types of attacks can F5-K000153074 enable?
F5-K000153074 can enable attackers to conduct HTTP response splitting attacks, potentially leading to cross-site scripting and cache poisoning.
How can I confirm if my system is vulnerable to F5-K000153074?
You can confirm if your system is vulnerable to F5-K000153074 by checking the version number of the affected F5 products against the specified vulnerable ranges.