VDB

BDU%3A2023-01738

BDU%3A2023-01738 PUBLISHED CVSS 10 CRITICAL

Уязвимость модуля mod_proxy веб-сервера Apache HTTP Server, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)

Risk Scores

CVSS 2.0
10

Affected Products

VendorProductVersions
ООО «РусБИТех-Астра», Novell Inc., Red Hat Inc., ООО «Ред Софт», АО «ИВК», Apache Software Foundation, АО «НТЦ ИТ РОСА», АО "НППКТ", АО «Концерн ВНИИНС»Astra Linux Special Edition (запись в едином реестре российских программ №369), Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, SUSE OpenStack Cloud, Suse Linux Enterprise Server, SUSE Linux Enterprise Module for Server Applications, HPE Helion Openstack, JBoss Core Services, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Server for Raspberry Pi, SUSE CaaS Platform, SUSE Manager Proxy, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Manager Server, Альт 8 СП (запись в едином реестре российских программ №4305), SUSE Manager Retail Branch Server, Red Hat Enterprise Linux, SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Storage, SUSE Package Hub, SUSE Linux Enterprise Module for Package Hub, HTTP Server, ROSA Virtualization (запись в едином реестре российских программ №5091), ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177), ROSA Virtualization 3.0 (запись в едином реестре российских программ №21308)

Timeline

  • Mar 30, 2023 CVE Published
  • Aug 19, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›