Improper Output Neutralization for Logs Affecting httpd:2.4/httpd-tools package, versions <0:2.4.37-47.module+el8.6.0+23463+5d5709c6.11


Severity

Recommended
medium

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.11% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Output Neutralization for Logs vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RHEL8-HTTPD-12647245
  • published12 Sept 2025
  • disclosed14 Jul 2025

Introduced: 14 Jul 2025

CVE-2024-47252  (opens in a new tab)
CWE-117  (opens in a new tab)

How to fix?

Upgrade RHEL:8 httpd:2.4/httpd-tools to version 0:2.4.37-47.module+el8.6.0+23463+5d5709c6.11 or higher.
This issue was patched in RHSA-2025:15698.

NVD Description

Note: Versions mentioned in the description apply only to the upstream httpd:2.4/httpd-tools package and not the httpd:2.4/httpd-tools package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations.

In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.

CVSS Base Scores

version 3.1