Apache Vulnerability

Our vulnerability tool indicates that your organization is suspected to be exposed to a vulnerability on the Apache HTTP Server versions 2.4.0 through 2.4.55.

This vulnerability allows a HTTP Request Smuggling attack. It can be tracked as CVE-2023-25690 and was given a base score of 9.8 by NIST, which is considered Critical.

Here are some additional resources provided by Apache to fix the vulnerability:

https://httpd.apache.org/security/vulnerabilities_24.html

https://nvd.nist.gov/vuln/detail/CVE-2023-25690

We recommend implementing those remediation tips if you confirm that your servers are exposed to the vulnerability.

Feel free to reach out to your client advocate for additional support.