Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.
This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.
Users are recommended to upgrade to version 2.4.66 which fixes the issue.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Http_server | Apache | 2.4.0 (including) | 2.4.66 (excluding) |
| JBoss Core Services for RHEL 8 | RedHat | jbcs-httpd24-httpd-0:2.4.62-11.el8jbcs | * |
| JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-httpd-0:2.4.62-11.el7jbcs | * |
| Red Hat Enterprise Linux 10 | RedHat | httpd-0:2.4.63-4.el10_1.3 | * |
| Red Hat Enterprise Linux 8 | RedHat | httpd:2.4-8100020251212173309.489197e6 | * |
| Red Hat Enterprise Linux 9 | RedHat | httpd-0:2.4.62-7.el9_7.3 | * |
| Red Hat JBoss Core Services 2.4.62.SP3 | RedHat | jbcs-httpd24-httpd | * |
| Apache2 | Ubuntu | devel | * |
| Apache2 | Ubuntu | jammy | * |
| Apache2 | Ubuntu | noble | * |
| Apache2 | Ubuntu | plucky | * |
| Apache2 | Ubuntu | questing | * |
| Apache2 | Ubuntu | upstream | * |