Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:1547 - Security Advisory
Issued:
2023-04-03
Updated:
2023-04-03

RHSA-2023:1547 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: httpd:2.4 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: HTTP request splitting with mod_rewrite and mod_proxy (CVE-2023-25690)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing the updated packages, the httpd daemon will be restarted automatically.

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 2176209 - CVE-2023-25690 httpd: HTTP request splitting with mod_rewrite and mod_proxy

CVEs

  • CVE-2023-25690

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
httpd-2.4.37-16.module+el8.1.0+18511+ffefe478.6.src.rpm SHA-256: dfb88ceebb3d4d3dd385b9bbfd55d1e77a926529f6ba2972fad9b190edcb70e6
mod_http2-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.src.rpm SHA-256: bc819bb5fcce08bf16b5f2a257c45a4f68da62e7947cdd1f98ed6b8cd0dbc976
ppc64le
httpd-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: 83bd8c8221897a526077a6f4ce75dbadc4a26564f1b3d5aa6807d5f1fb6a3d40
httpd-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: 6115482dc0de353150ab2b63df328a91d5c3a9d84785fbf3f0f219269004e8c0
httpd-debugsource-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: e936e89ed4015eb8878a197755379ceec96c3497c630c7854fc0b8f54532862b
httpd-devel-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: bd43b9fd8f95bd7392e09fc1b04c068d2b8321918934a1ca8079bf58ce863b1d
httpd-filesystem-2.4.37-16.module+el8.1.0+18511+ffefe478.6.noarch.rpm SHA-256: 0e92bb5352ca348bf492a3d88b63e874f7c3e9282685ee653d8f596e597b6eba
httpd-manual-2.4.37-16.module+el8.1.0+18511+ffefe478.6.noarch.rpm SHA-256: 78efb83e17d494e088939d423ef3f8e0ccc974c908ee2fd3f926dcc144e842ab
httpd-tools-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: f643d1873e5dd5cd16de620efc1e1e4f897cfb94844f28a60c752a583f41ce95
httpd-tools-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: 12406a7136fe51902775e094f4996503dc63f436ffbfc720bfa1da020f4de420
mod_http2-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.ppc64le.rpm SHA-256: 62668734af7c0cc9352bca0670c31d0e7f1da2a3d9da9c8eec16f90404eb3ab2
mod_http2-debuginfo-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.ppc64le.rpm SHA-256: fd1e74dbc997af2a57e9cff6d4da33b89e60ae3be4d303b824330fad681407c3
mod_http2-debugsource-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.ppc64le.rpm SHA-256: 90808b4cde3af62cff828058dcca32ec90d0068ee7db2a0cd1ead491b36c2ff4
mod_ldap-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: a48a111b90ff233a06bf365aa8959e02e9a39da3a60567c295f1376d86d556d1
mod_ldap-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: a95eec37ade2902bd5acc7ad6e1b9cf9b257f161e92cd228348ba60bbd676f44
mod_md-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: 77e1cdd980c23b4c9f8e30092856912457b559947181f5152065a0aed2313d82
mod_md-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: d5b0328a12800b4e8f7fb1e7d4d9c51b56de3823a391904d14a0c1380bc8ce4d
mod_proxy_html-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: 641f2c881b2f6e01963a5d1d8859aaf690fc3694b90826ee9d2b9d1a99a33ef9
mod_proxy_html-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: d217e3a1cfc326b8995893fe0af4301a0dd483465f55d0565e763efbf6001844
mod_session-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: 78eba12c7550c2cf2147bab4bf653f707eb488fc03f3d10e9e5c2ab3522f7e17
mod_session-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: e2a391f42aaf732b5df45db1fd7d4661ddd5e7d7aec5a240e1836f09dc31a831
mod_ssl-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: c46c5c4b4f1f6646b67901a40b3e299d18ef6ebf29c055bd9a389c766bafcf32
mod_ssl-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.ppc64le.rpm SHA-256: e530e7d81452f52587064899447124d921d8231e691202930335b37254ae2d5d

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
httpd-2.4.37-16.module+el8.1.0+18511+ffefe478.6.src.rpm SHA-256: dfb88ceebb3d4d3dd385b9bbfd55d1e77a926529f6ba2972fad9b190edcb70e6
mod_http2-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.src.rpm SHA-256: bc819bb5fcce08bf16b5f2a257c45a4f68da62e7947cdd1f98ed6b8cd0dbc976
x86_64
httpd-filesystem-2.4.37-16.module+el8.1.0+18511+ffefe478.6.noarch.rpm SHA-256: 0e92bb5352ca348bf492a3d88b63e874f7c3e9282685ee653d8f596e597b6eba
httpd-manual-2.4.37-16.module+el8.1.0+18511+ffefe478.6.noarch.rpm SHA-256: 78efb83e17d494e088939d423ef3f8e0ccc974c908ee2fd3f926dcc144e842ab
httpd-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 5c1ff5d5a640b11dacd1ac6b9961ac58b96e75c07e2d40192114dad1968c0dc1
httpd-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 6003ddec384a22eb948dfb7aac2a4b997b7a50cf58dc4e0a0ca0a225d06b1f39
httpd-debugsource-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 954db4eaad1b295cb1cd74ab1d8d5d286967526801859bca5a0a5f636e537594
httpd-devel-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: a0c80c8d10ee4cc4ae482123e00474f7e81abddbf9f43958af28cb676d3677f6
httpd-tools-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: dd72521bdda5412f8f51bad84b83e80aca2dfe28fb1c2749ef3e2d2ced369cb1
httpd-tools-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: c2dfbba442981a7290f4fdabe919e616efb0d81922d2f848059797480ca10eff
mod_http2-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.x86_64.rpm SHA-256: f9f4c22b52a6ffb87939433958752a3c3a085a366d8009a989c34e4618cf9d80
mod_http2-debuginfo-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.x86_64.rpm SHA-256: 704d5a75b8e7b7523a28d80b7a902e01eee440e66cc711f8776b9a08f0398533
mod_http2-debugsource-1.11.3-3.module+el8.1.0+18514+ae5f89d3.3.x86_64.rpm SHA-256: fb78005aa20a97a604780fac8b1499a3ccfaaf2abf3327dfd8c95710f27b5ded
mod_ldap-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 03b406f5233fad21acb34940dfb5e808add36768f35d6423c03042a5a709cf5d
mod_ldap-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 11514044b9748195271158844764a31b6f40d5ccb4fb0d9582d57835caf104ef
mod_md-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 3ce20c6a88d70f07188242caac3cc7c6ca2d0c32dd4fc4cdf0b63dedc974d4c3
mod_md-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: b4af27291b7846bf2e486a428bbcc6fcebee9005c3e81ccc60e4ed1f9d133f5d
mod_proxy_html-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: ea69d756ef373f78323e3ecae88852b0d7e11e57ca57b5d0891cd417a79a86f5
mod_proxy_html-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 857046ead95282f2fa9755d55d459328f99f4cb712a619ae73a12e238d5748ef
mod_session-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 68ead92c450c96f69db4c735a83ffc75ca95d381e56a4ba1160e17544ea8d849
mod_session-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 04de3390fcdf96c880f66c8ae7a7e9b0b606433d532facaec122527f5e255f37
mod_ssl-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: d4b0d6d1738590ff846163ef8498559008c17c81c3647d0868ecc1edc54972ee
mod_ssl-debuginfo-2.4.37-16.module+el8.1.0+18511+ffefe478.6.x86_64.rpm SHA-256: 3d5826564f6b7580d1c35ab651bdce3ea5ff0b0dca7d18d25583b88cb48c341b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility