CVE-2023-25690
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
描述
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.
如何修補 CVE-2023-25690
要修補 CVE-2023-25690,請將受影響套件升級到下列已修補版本。
- —升級至 2.4.56-r0 或更新版本
- —升級至 2.4.56 或更新版本
- —升級至 2.4.56-1~deb11u1 或更新版本
- —升級至 2.4.38-3+deb10u10 或更新版本
CVE-2023-25690 正在被利用嗎?
可能 — EPSS 為 83.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(4)
- from 0, < 2.4.56-r0
- >= 2.4.0, < 2.4.56
- from 0, < 2.4.56-1~deb11u1
- from 0, < 2.4.38-3+deb10u10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |