Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).
{
"cpe": [
"cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.6:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.8:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.9:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.10:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.11:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.12:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.13:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.14:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.15:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.16:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.17:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.18:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.19:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.20:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.21:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.22:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.23:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.24:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.25:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.26:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.27:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.29:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.2.31:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.2:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.3:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.4:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.6:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.7:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.9:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.10:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.12:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.16:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.17:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.20:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:http_server:2.4.23:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.2.0"
},
{
"last_affected": "2.2.2"
},
{
"last_affected": "2.2.3"
},
{
"last_affected": "2.2.4"
},
{
"last_affected": "2.2.6"
},
{
"last_affected": "2.2.8"
},
{
"last_affected": "2.2.9"
},
{
"last_affected": "2.2.10"
},
{
"last_affected": "2.2.11"
},
{
"last_affected": "2.2.12"
},
{
"last_affected": "2.2.13"
},
{
"last_affected": "2.2.14"
},
{
"last_affected": "2.2.15"
},
{
"last_affected": "2.2.16"
},
{
"last_affected": "2.2.17"
},
{
"last_affected": "2.2.18"
},
{
"last_affected": "2.2.19"
},
{
"last_affected": "2.2.20"
},
{
"last_affected": "2.2.21"
},
{
"last_affected": "2.2.22"
},
{
"last_affected": "2.2.23"
},
{
"last_affected": "2.2.24"
},
{
"last_affected": "2.2.25"
},
{
"last_affected": "2.2.26"
},
{
"last_affected": "2.2.27"
},
{
"last_affected": "2.2.29"
},
{
"last_affected": "2.2.31"
},
{
"last_affected": "2.4.1"
},
{
"last_affected": "2.4.2"
},
{
"last_affected": "2.4.3"
},
{
"last_affected": "2.4.4"
},
{
"last_affected": "2.4.6"
},
{
"last_affected": "2.4.7"
},
{
"last_affected": "2.4.9"
},
{
"last_affected": "2.4.10"
},
{
"last_affected": "2.4.12"
},
{
"last_affected": "2.4.16"
},
{
"last_affected": "2.4.17"
},
{
"last_affected": "2.4.18"
},
{
"last_affected": "2.4.20"
},
{
"last_affected": "2.4.23"
}
]
}