Release of Apache HTTP Server 2.4.56 with vulnerability fixes

The release of Apache HTTP Server 2.4.56 has been published, featuring 6 changes and addressing 2 vulnerabilities related to potential HTTP Request Smuggling attacks on frontend-backend systems, allowing interference with the contents of requests from other users being processed in the same stream between the frontend and backend. This attack can be used to bypass access restrictions or inject malicious JavaScript code into a session with a legitimate site.

The first vulnerability (CVE-2023-27522) affects the mod_proxy_uwsgi module and allows the proxy side to split the response into two parts by substituting special characters in the HTTP header returned by the backend.

The second vulnerability (CVE-2023-25690) exists in mod_proxy and manifests when using certain rewrite rules via the RewriteRule directive provided by the mod_rewrite module, or specific patterns in the ProxyPassMatch directive. This vulnerability can lead to proxy requests to internal resources that are restricted through the proxy or to cache content poisoning. To manifest the vulnerability, the rewrite rules must use data from the URL that is then substituted in the forwarded request. For example: RewriteEngine on RewriteRule "^\/here\/(.*)" " http:\/\/example.com:8080\/elsewhere?$1" http:\/\/example.com:8080\/elsewhere ; [P] ProxyPassReverse \/here\/ http:\/\/example.com:8080\/ http:\/\/example.com:8080\/

Among the changes unrelated to security:

  • The rotatelogs utility has been enhanced with the ‘-T’ flag, allowing for the truncation of subsequent log files without truncating the initial log file during log rotation.
  • In mod_ldap, specifying negative values in the LDAPConnectionPoolTTL directive is now allowed to configure the reuse of any old connections.
  • In the mod_md module, used for automating the acquisition and maintenance of certificates using the ACME (Automatic Certificate Management Environment) protocol, support for the ED25519 digital signature scheme and accounting for certificate transparency (CT) log information has been included when built with libressl 3.5.0+. The MDChallengeDns01 directive allows for defining settings for individual domains.
  • In mod_proxy_uwsgi, the checking and parsing of responses from HTTP backends has been tightened.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster