Home

Description

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.

PUBLISHED Reserved 2024-09-23 | Published 2025-07-10 | Updated 2025-11-04 | Assigner apache

Problem types

CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences

Product status

Default status
unaffected

2.4 (semver)
affected

Timeline

2024-09-18:reported

Credits

John Runyon finder

References

lists.debian.org/debian-lts-announce/2025/08/msg00009.html

www.openwall.com/lists/oss-security/2025/07/10/2

www.openwall.com/lists/oss-security/2025/07/10/6

httpd.apache.org/security/vulnerabilities_24.html vendor-advisory

cve.org (CVE-2024-47252)

nvd.nist.gov (CVE-2024-47252)

Download JSON