SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-24795

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.

MEDIUM 6.3EPSS 2.87%

Does this matter?

Lower severity and a low EPSS score (2.87%). Track it; it rarely justifies an emergency change on its own.

Description

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS
2.87% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-113, CWE-444
Affected
apache/http server · debian/debian linux · fedoraproject/fedora · netapp/ontap · netapp/ontap tools · broadcom/fabric operating system · apple/macos
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.