Severity: moderate

Description:

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response 
headers to be truncated early, resulting in some headers being incorporated 
into the response body. If the later headers have any security purpose, they 
will not be interpreted by the client.

Credit:

Dimas Fariski Setyawan Putra (@nyxsorcerer) (finder)

References:

https://httpd.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-37436

Timeline:

2022-07-14: Reported to security team


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org
For additional commands, e-mail: users-h...@httpd.apache.org

Reply via email to