REDHAT-BUG-2374571: Medium severity Apache HTTP Server vulnerability

Published Jun 24, 2025
·
Updated

Insufficient escaping of user-supplied data in modssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with \"%{varname}x\" or \"%{varname}c\" to log variables provided by modssl such as SSLTLSSNI, no escaping is performed by either modlogconfig or modssl and unsanitized data provided by the client may appear in log files.

Affected Software

1 affected component
Apache HTTP Server<2.4.63

Event History

Jun 24, 2025
Data Sourced
via Red Hat·01:15 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2374571?

The severity of REDHAT-BUG-2374571 is considered high due to potential risks associated with insufficient data escaping in logging.

2

How do I fix REDHAT-BUG-2374571?

To fix REDHAT-BUG-2374571, upgrade to Apache HTTP Server version 2.4.64 or later, where the issue has been addressed.

3

What configurations are affected by REDHAT-BUG-2374571?

REDHAT-BUG-2374571 affects configurations using CustomLog with the "%{varname}x" or "%{varname}c" directives in Apache HTTP Server.

4

Who should be concerned about REDHAT-BUG-2374571?

Administrators using Apache HTTP Server versions 2.4.63 and earlier should be concerned about REDHAT-BUG-2374571.

5

What risk does REDHAT-BUG-2374571 pose?

REDHAT-BUG-2374571 poses a risk of exposing sensitive data through improperly logged information due to untrusted SSL/TLS client inputs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203