A vulnerability related to Apache HTTP Server has just published.
The version of Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
Affected Systems
IoC’s
-
Recommended Solution(s)
It is highly recommended to upgrade Apache HTTP Server version 2.5.54 (2022-06-08).
It is recommended to check up on the content in the links below:
https://httpd.apache.org/security/vulnerabilities_24.htmlCVE / CWE
CVE-2022-31813
Related Website(s)
* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.