Description
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.
Problem types
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
Product status
2.4 (semver)
Timeline
| 2024-09-18: | reported |
Credits
John Runyon
References
lists.debian.org/debian-lts-announce/2025/08/msg00009.html
www.openwall.com/lists/oss-security/2025/07/10/2
www.openwall.com/lists/oss-security/2025/07/10/6
httpd.apache.org/security/vulnerabilities_24.html