RHSA-2023:1673: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: HTTP request splitting with modrewrite and modproxy (CVE-2023-25690) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-51.module+el8.7.0+18499+2e106f0b.5.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch httpd:2.4 security update
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1673?
The severity of RHSA-2023:1673 is considered high due to the potential for HTTP request splitting.
How do I fix RHSA-2023:1673?
To fix RHSA-2023:1673, update the httpd package to version 2.4.37-51.module+el8.7.0+18499+2e106f0b.5 or later.
What versions of httpd are affected by RHSA-2023:1673?
Affected versions for RHSA-2023:1673 include any versions prior to 2.4.37-51.module+el8.7.0+18499+2e106f0b.5.
What is CVE-2023-25690 in relation to RHSA-2023:1673?
CVE-2023-25690 relates to an HTTP request splitting vulnerability in the httpd server's mod_rewrite and mod_proxy modules.
Does RHSA-2023:1673 require immediate action?
Yes, immediate action is recommended to mitigate the risk of exploitation due to the identified vulnerability.