VDB

GCVE-110-MAGEIA-2023-100

GCVE-110-MAGEIA-2023-100
Advisory Published
Vulnetix · Advisory published March 18, 2023
Some mod_proxy configurations on Apache HTTP Server allow a HTTP request smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. (CVE-2023-25690) HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server. Special characters in the origin response header can truncate/split the response forwarded to the client. (CVE-2023-27522)

Affected Products

VendorProductVersionsPlatforms
Mageiaapache2.4.56-1.mga8 (unaffected), 2.4.56-1.mga8 (unaffected), 0 (affected), 0 (affected)
Mageialiquidshell0 (affected), 1.8.1-1.1.mga9 (unaffected)

Browse GCVE Records

77,901 records in the GCVE database · Updated August 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›