Description
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
Remediation
References
Related Vulnerabilities
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9515)
WordPress Plugin My Wish List Cross-Site Scripting (1.4.1)
XWiki Improper Privilege Management Vulnerability (CVE-2023-26475)
WebLogic CVE-2023-22031 Vulnerability (CVE-2023-22031)
WordPress Plugin WordPress Email Template Designer-WP HTML Mail HTML Injection (2.9.0.3)