CVE-2005-2088
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 20.46% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-444
- Affected
- apache/http server · debian/debian linux
- Source
- secalert@redhat.com
References
- http://docs.info.apple.com/article.html?artnum=302847Broken Link
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlBroken Link
- http://marc.info/?l=apache-httpd-announce&m=112931556417329&w=3Mailing List, Third Party Advisory
- http://seclists.org/lists/bugtraq/2005/Jun/0025.htmlIssue Tracking, Mailing List, Third Party Advisory
- http://secunia.com/advisories/14530Not Applicable
- http://secunia.com/advisories/17319Not Applicable
- http://secunia.com/advisories/17487Not Applicable
- http://secunia.com/advisories/17813Not Applicable
- http://secunia.com/advisories/19072Not Applicable
- http://secunia.com/advisories/19073Not Applicable
- http://secunia.com/advisories/19185Not Applicable
- http://secunia.com/advisories/19317Not Applicable
- http://secunia.com/advisories/23074Not Applicable
- http://securityreason.com/securityalert/604Exploit, Third Party Advisory
- http://securitytracker.com/id?1014323Broken Link, Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.600000Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-081.htmThird Party Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=PK13959&apar=onlyBroken Link, Third Party Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=onlyBroken Link, Third Party Advisory
- http://www.apache.org/dist/httpd/CHANGES_1.3Broken Link, Vendor Advisory
- http://www.apache.org/dist/httpd/CHANGES_2.0Broken Link, Vendor Advisory
- http://www.debian.org/security/2005/dsa-803Mailing List, Third Party Advisory
- http://www.debian.org/security/2005/dsa-805Mailing List, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:130Third Party Advisory
- http://www.novell.com/linux/security/advisories/2005_18_sr.htmlBroken Link
- http://www.novell.com/linux/security/advisories/2005_46_apache.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-582.htmlBroken Link, Third Party Advisory
- http://www.securiteam.com/securityreviews/5GP0220G0U.htmlBroken Link, Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.