Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
History

Mon, 30 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Broadcom
Broadcom fabric Operating System
Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora
Netapp
Netapp ontap
Netapp ontap Tools
CPEs cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:fabric_operating_system:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Broadcom
Broadcom fabric Operating System
Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora
Netapp
Netapp ontap
Netapp ontap Tools

Wed, 13 Nov 2024 02:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9

Tue, 05 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache http Server
Weaknesses CWE-1284
CPEs cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache http Server
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Tue, 24 Sep 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Core Services
CPEs cpe:/a:redhat:jboss_core_services:1
cpe:/a:redhat:jboss_core_services:1::el7
cpe:/a:redhat:jboss_core_services:1::el8
Vendors & Products Redhat jboss Core Services

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-04-04T19:19:35.467Z

Updated: 2025-02-13T17:02:32.587Z

Reserved: 2023-07-24T17:51:18.042Z

Link: CVE-2023-38709

cve-icon Vulnrichment

Updated: 2024-08-02T17:46:56.949Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-04T20:15:08.047

Modified: 2025-06-30T12:59:08.537

Link: CVE-2023-38709

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-04T00:00:00Z

Links: CVE-2023-38709 - Bugzilla