Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
References
Link | Resource |
---|---|
https://httpd.apache.org/security/vulnerabilities_24.html | Release Notes Vendor Advisory |
https://security.gentoo.org/glsa/202309-01 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apache
Published: 2023-01-17T19:12:59.968Z
Updated: 2023-09-08T21:06:24
Reserved: 2022-08-05T12:37:59.731Z
Link: CVE-2022-37436
JSON object: View
NVD Information
Status : Modified
Published: 2023-01-17T20:15:11.670
Modified: 2023-09-08T22:15:10.340
Link: CVE-2022-37436
JSON object: View
Redhat Information
No data.