Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:3292 - Security Advisory
Issued:
2023-05-24
Updated:
2023-05-24

RHSA-2023:3292 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: httpd24-httpd security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for httpd24-httpd is now available for Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: HTTP request splitting with mod_rewrite and mod_proxy (CVE-2023-25690)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing the updated packages, the httpd daemon will be restarted automatically.

Affected Products

  • Red Hat Software Collections (for RHEL Server) 1 for RHEL 7 x86_64
  • Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7 s390x
  • Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7 ppc64le
  • Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7 x86_64

Fixes

  • BZ - 2176209 - CVE-2023-25690 httpd: HTTP request splitting with mod_rewrite and mod_proxy

CVEs

  • CVE-2023-25690

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Software Collections (for RHEL Server) 1 for RHEL 7

SRPM
httpd24-httpd-2.4.34-23.el7.6.src.rpm SHA-256: 6c693486166afd2db98a192e15e066815497852d1a1b829cd88b1db8941b90a4
x86_64
httpd24-httpd-2.4.34-23.el7.6.x86_64.rpm SHA-256: d04aed76b461e887b3383efdc6da8c3bdbeaa80630f0ea18ed764f30eef6bc2a
httpd24-httpd-debuginfo-2.4.34-23.el7.6.x86_64.rpm SHA-256: ec90257163dadc4f479da1e0710aa0a98995ca62ab5b3095f5cf3725f7859062
httpd24-httpd-devel-2.4.34-23.el7.6.x86_64.rpm SHA-256: b1f6668b598c6e23029b32af0aa6733e9733c595197b38746d9a886e991c32a2
httpd24-httpd-manual-2.4.34-23.el7.6.noarch.rpm SHA-256: f07cfeeacc8ff85ec3ba3edd2dfe6343a14c8673a9c55478d1f8e8614265e94e
httpd24-httpd-tools-2.4.34-23.el7.6.x86_64.rpm SHA-256: 88dbd221517a3d13bdb69c69ffc93b91269c016f84d100a3e7c0a2dfcd645198
httpd24-mod_ldap-2.4.34-23.el7.6.x86_64.rpm SHA-256: 3398b4ae96858861959a3945c8650085d07f72bcc0d6b6e34b82fe80ee3a1c0b
httpd24-mod_proxy_html-2.4.34-23.el7.6.x86_64.rpm SHA-256: 01fbf418a595dd95647104e56ddd8c5f350d1a84837ebc8b8f8419699c9cad31
httpd24-mod_session-2.4.34-23.el7.6.x86_64.rpm SHA-256: ca9b057e7163ee7c72eeacbee2bfad97a32c7fc35c222b34918d950b14a16f2b
httpd24-mod_ssl-2.4.34-23.el7.6.x86_64.rpm SHA-256: 56f8f497a9778a1eb3b655b2e7972308caa130e29bda39d0989286a2bfe767fe

Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7

SRPM
httpd24-httpd-2.4.34-23.el7.6.src.rpm SHA-256: 6c693486166afd2db98a192e15e066815497852d1a1b829cd88b1db8941b90a4
s390x
httpd24-httpd-2.4.34-23.el7.6.s390x.rpm SHA-256: 9dffd34d442ad0ff6cf2e836799577234dc98c39191a02f408cda3dcd50fae28
httpd24-httpd-debuginfo-2.4.34-23.el7.6.s390x.rpm SHA-256: 58327c6145d7cdf919f46999698622ea0811bd55f64a694cbb5a5261ff383c17
httpd24-httpd-devel-2.4.34-23.el7.6.s390x.rpm SHA-256: 0fe34f39839a9ed495ebdb35f4dbf809eec2b0e0a8ec4e04480cc179124a4a46
httpd24-httpd-manual-2.4.34-23.el7.6.noarch.rpm SHA-256: f07cfeeacc8ff85ec3ba3edd2dfe6343a14c8673a9c55478d1f8e8614265e94e
httpd24-httpd-tools-2.4.34-23.el7.6.s390x.rpm SHA-256: 243d5a3192ec0930071cc5efdbacd6d8a620569929f648d70ae41065d4ab6ce1
httpd24-mod_ldap-2.4.34-23.el7.6.s390x.rpm SHA-256: d41184c0523ea57d84dc264d537112fc21a8cde2cfe2cdc5b7f30c1472b0e9a8
httpd24-mod_proxy_html-2.4.34-23.el7.6.s390x.rpm SHA-256: 1301f81515b1793541953fd01ff497568f0facc397fd6bca3932c93b921f2e5b
httpd24-mod_session-2.4.34-23.el7.6.s390x.rpm SHA-256: 07ce721d8d85273caf6e184f8dd8fa11afdd4387e76468aae8202dfa739a2d41
httpd24-mod_ssl-2.4.34-23.el7.6.s390x.rpm SHA-256: 5847325758c6870f276cffc210036b036ae0996e39f2e1647409c3d1bf1f40f9

Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7

SRPM
httpd24-httpd-2.4.34-23.el7.6.src.rpm SHA-256: 6c693486166afd2db98a192e15e066815497852d1a1b829cd88b1db8941b90a4
ppc64le
httpd24-httpd-2.4.34-23.el7.6.ppc64le.rpm SHA-256: 1b735cde4107fe3c2d4db1c71a86923a028e82ea5c53e495043a7c86ea6b643a
httpd24-httpd-debuginfo-2.4.34-23.el7.6.ppc64le.rpm SHA-256: b9a5f473a2a33694f138bf4510cfa4886cc4a2e0ad23b4e658207858ba494542
httpd24-httpd-devel-2.4.34-23.el7.6.ppc64le.rpm SHA-256: 2075003e101b9a8e4d6e6a76c2fc70e247360e9892ae494ed89f1aaf628e7b7e
httpd24-httpd-manual-2.4.34-23.el7.6.noarch.rpm SHA-256: f07cfeeacc8ff85ec3ba3edd2dfe6343a14c8673a9c55478d1f8e8614265e94e
httpd24-httpd-tools-2.4.34-23.el7.6.ppc64le.rpm SHA-256: c5cb9142fd9d069e3f73a2d310ac3f02f9590ebd27c7edbb7c72ddaf1264eb3b
httpd24-mod_ldap-2.4.34-23.el7.6.ppc64le.rpm SHA-256: 8b54506960a6373e1367300a0e2bcdb719a3659c6bf9e9f43eeaca636d2a6ce4
httpd24-mod_proxy_html-2.4.34-23.el7.6.ppc64le.rpm SHA-256: ace48e9cb1a0b567f2f346b6b30ee8fa1eedab5f5cc7f64a0f997a826c4e7583
httpd24-mod_session-2.4.34-23.el7.6.ppc64le.rpm SHA-256: 6e4b0bd0267c6ce4eb31aa123cdf7cea31ccc083772d240849e4283c2fcc5400
httpd24-mod_ssl-2.4.34-23.el7.6.ppc64le.rpm SHA-256: c38d99d9a4557d4b4d71f5f218c2b7f8a1786399f72f2663a00f56ae604951f9

Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7

SRPM
httpd24-httpd-2.4.34-23.el7.6.src.rpm SHA-256: 6c693486166afd2db98a192e15e066815497852d1a1b829cd88b1db8941b90a4
x86_64
httpd24-httpd-2.4.34-23.el7.6.x86_64.rpm SHA-256: d04aed76b461e887b3383efdc6da8c3bdbeaa80630f0ea18ed764f30eef6bc2a
httpd24-httpd-debuginfo-2.4.34-23.el7.6.x86_64.rpm SHA-256: ec90257163dadc4f479da1e0710aa0a98995ca62ab5b3095f5cf3725f7859062
httpd24-httpd-devel-2.4.34-23.el7.6.x86_64.rpm SHA-256: b1f6668b598c6e23029b32af0aa6733e9733c595197b38746d9a886e991c32a2
httpd24-httpd-manual-2.4.34-23.el7.6.noarch.rpm SHA-256: f07cfeeacc8ff85ec3ba3edd2dfe6343a14c8673a9c55478d1f8e8614265e94e
httpd24-httpd-tools-2.4.34-23.el7.6.x86_64.rpm SHA-256: 88dbd221517a3d13bdb69c69ffc93b91269c016f84d100a3e7c0a2dfcd645198
httpd24-mod_ldap-2.4.34-23.el7.6.x86_64.rpm SHA-256: 3398b4ae96858861959a3945c8650085d07f72bcc0d6b6e34b82fe80ee3a1c0b
httpd24-mod_proxy_html-2.4.34-23.el7.6.x86_64.rpm SHA-256: 01fbf418a595dd95647104e56ddd8c5f350d1a84837ebc8b8f8419699c9cad31
httpd24-mod_session-2.4.34-23.el7.6.x86_64.rpm SHA-256: ca9b057e7163ee7c72eeacbee2bfad97a32c7fc35c222b34918d950b14a16f2b
httpd24-mod_ssl-2.4.34-23.el7.6.x86_64.rpm SHA-256: 56f8f497a9778a1eb3b655b2e7972308caa130e29bda39d0989286a2bfe767fe

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility