VDB
BDU%3A2023-02021
BDU%3A2023-02021
PUBLISHED
CVSS 9 CRITICAL
Уязвимость компонента mod_proxy_uwsgi веб-сервера Apache HTTP Server связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю выполнять атаку "контрабанда HTTP-запросов"
Risk Scores
CVSS 2.0
9
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, Canonical Ltd., ООО «Ред Софт», АО «ИВК», Apache Software Foundation, АО «НТЦ ИТ РОСА», АО "НППКТ", АО «Концерн ВНИИНС» | Astra Linux Special Edition (запись в едином реестре российских программ №369), Red Hat Enterprise Linux, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Module for Server Applications, Debian GNU/Linux, JBoss Core Services, SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Server, Ubuntu, SUSE Linux Enterprise Module for Basesystem, SUSE Manager Proxy, SUSE Manager Retail Branch Server, SUSE Manager Server, РЕД ОС (запись в едином реестре российских программ №3751), Suse Linux Enterprise Desktop, Альт 8 СП (запись в едином реестре российских программ №4305), SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Storage, SUSE Package Hub, SUSE Linux Enterprise Module for Package Hub, HTTP Server, ROSA Virtualization (запись в едином реестре российских программ №5091), ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177), ROSA Virtualization 3.0 (запись в едином реестре российских программ №21308) |
Timeline
- Apr 13, 2023 CVE Published
- Aug 19, 2025 CVE Updated
References
- https://httpd.apache.org/security/vulnerabilities_24.html url
- https://security-tracker.debian.org/tracker/CVE-2023-27522 url
- https://access.redhat.com/security/cve/cve-2023-27522 url
- https://redos.red-soft.ru/support/secure/ url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2023-0426SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2023-0727SE47 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.8/ url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#20102023 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2859 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2851 url
- http://httpd.apache.org/security/vulnerabilities_24.html advisory
- https://ubuntu.com/security/CVE-2023-27522 advisory
- https://www.suse.com/security/cve/CVE-2023-27522.html advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20231214SE16 advisory
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2860 advisory