Description
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
Remediation
References
Related Vulnerabilities
Magento Session Fixation Vulnerability (CVE-2019-8116)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2023-39456)
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2022-28660)
Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949)
WordPress Plugin WP Database Backup Cross-Site Scripting (3.3)