oss-sec mailing list archives
CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable escaping
From: Eric Covener <covener () apache org>
Date: Thu, 10 Jul 2025 17:13:54 +0000
Severity: low
Affected versions:
- Apache HTTP Server 2.4 through 2.4.63
Description:
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted
SSL/TLS client to insert escape characters into log files in some configurations.
In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by
mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided
by the client may appear in log files.
Credit:
John Runyon (finder)
References:
https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-47252
Timeline:
2024-09-18: reported
2025-07-07: 2.4.x revision 1927042
Current thread:
- CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable escaping Eric Covener (Jul 10)
