Description
Two potential security issues have been fixed in Apache version 1.3.34:
- If a request contains both Transfer-Encoding and Content-Length headers, remove the Content-Length, mitigating some HTTP Request Splitting/Spoofing attacks.
- Added TraceEnable [on|off|extended] per-server directive to alter the behavior of the TRACE method.
Remediation
Upgrade Apache to the latest version.
References
Related Vulnerabilities
MongoDb Improper Handling of Exceptional Conditions Vulnerability (CVE-2020-7926)
Atlassian Jira Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-39127)
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-33926)
WebLogic CVE-2019-2645 Vulnerability (CVE-2019-2645)
WordPress Plugin Contus HD FLV Player 'process-sortable.php' SQL Injection (1.3)