RHSA-2023:1597: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: HTTP request splitting with modrewrite and modproxy (CVE-2023-25690) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
mod_sslto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
mod_http2to a version that resolves this vulnerability.Fixed in 1.15.7-5.module+el8.6.0+18506+34b194fb.2 - Upgrade
Upgrade
mod_ldapto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
mod_proxy_htmlto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
mod_sessionto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4 - Upgrade
Upgrade
mod_mdto a version that resolves this vulnerability.Fixed in 2.0.8-8.module+el8.3.0+6814+67d1e611 - Upgrade
Upgrade
httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+18507+843660a1.4
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1597?
The severity of RHSA-2023:1597 is considered critical due to HTTP request splitting vulnerabilities.
What does CVE-2023-25690 in RHSA-2023:1597 refer to?
CVE-2023-25690 refers to a vulnerability that allows HTTP request splitting through the use of mod_rewrite and mod_proxy in httpd.
How do I fix RHSA-2023:1597?
To fix RHSA-2023:1597, update the httpd package to version 2.4.37-47.module+el8.6.0+18507+843660a1.4 or higher.
Which packages are affected by RHSA-2023:1597?
The affected packages include httpd, httpd-debuginfo, httpd-tools, and several other related packages in the specified version range.
Is RHSA-2023:1597 related to Apache HTTP Server vulnerabilities?
Yes, RHSA-2023:1597 is related to vulnerabilities in the Apache HTTP Server that could allow for HTTP request splitting.