RHSA-2023:1596: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: HTTP request splitting with modrewrite and modproxy (CVE-2023-25690) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+18509+78723510.6.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch httpd:2.4 security update
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1596?
The severity of RHSA-2023:1596, which addresses HTTP request splitting in Apache HTTP Server, is considered to be significant due to the potential impact on web applications.
How do I fix RHSA-2023:1596?
To fix RHSA-2023:1596, update the httpd package to version 2.4.37-39.module+el8.4.0+18509+78723510.6 or later.
What is the main vulnerability addressed in RHSA-2023:1596?
RHSA-2023:1596 addresses a vulnerability that allows HTTP request splitting when using mod_rewrite and mod_proxy in Apache HTTP Server.
Which packages are affected by RHSA-2023:1596?
Affected packages include httpd, httpd-filesystem, httpd-manual, and several related packages in the specified versions.
Is there a workaround for RHSA-2023:1596?
There is no official workaround for RHSA-2023:1596, so users are strongly advised to apply the security update.