CVE-2023-38709

Aliases:ALPINE-CVE-2023-38709RHSA-2024:4197DEBIAN-CVE-2023-38709
Advisory lineage Upstream: 0 Downstream: 18
Modified
Published: 04 Apr 2024, 19:19
Last modified:04 Nov 2025, 21:08

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.3 HIGH
v3.1 (cve.org)
EPSS Score
3.91% LOW
4% probability +0.66%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Apr 2024, 19:19
Published
Vulnerability first disclosed
04 Nov 2025, 21:08
Last Modified
Vulnerability information updated

Description

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

CVSS Metrics

  • v3.1HIGHScore: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • v3.1MEDIUMScore: 6.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 3.91% Percentile: 90%

Techniques & Countermeasures

  • CWE-1284Improper Validation of Specified Quantity in Input

    The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Affected Systems

  • apache software foundationapache http server

    ≤ 2.4.58

  • apachehttp_server

    < 2.4.59

  • alpineapache2

    < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0

  • applemacos

    < 14.6

  • broadcomfabric_operating_system

    na

  • debianapache2

    < 2.4.59-1~deb11u1 | < 2.4.59-1~deb12u1 | < 2.4.59-1 | < 2.4.59-1

  • debiandebian_linux

    10.0

  • fedoraprojectfedora

    38 | 39 | 40

  • netappontap

    9

  • netappontap_tools

    10

  • redhathttpd

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhathttpd-debuginfo

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhathttpd-debugsource

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhathttpd-devel

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhathttpd-filesystem

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhathttpd-manual

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhathttpd-tools

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhathttpd-tools-debuginfo

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_http2

    < 0:1.15.7-10.module+el8.10.0+21653+eaff63f0

  • redhatmod_http2-debuginfo

    < 0:1.15.7-10.module+el8.10.0+21653+eaff63f0

  • redhatmod_http2-debugsource

    < 0:1.15.7-10.module+el8.10.0+21653+eaff63f0

  • redhatmod_ldap

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_ldap-debuginfo

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_md

    < 1:2.0.8-8.module+el8.9.0+19080+567b90f8

  • redhatmod_md-debuginfo

    < 1:2.0.8-8.module+el8.9.0+19080+567b90f8

  • redhatmod_md-debugsource

    < 1:2.0.8-8.module+el8.9.0+19080+567b90f8

  • redhatmod_proxy_html

    < 1:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_proxy_html-debuginfo

    < 1:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_session

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_session-debuginfo

    < 0:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_ssl

    < 1:2.4.37-65.module+el8.10.0+21982+14717793

  • redhatmod_ssl-debuginfo

    < 1:2.4.37-65.module+el8.10.0+21982+14717793

References (21)