Odin HomeODIN logoODIN logo
PricingJoin us on Discord
TableJSON

Products

Cyble Vision
Cyber threat intelligence platform
Cyble Hawk
Threat detection and intelligence capabilities built for federal bodies
AmIBreached
Identify, Prioritize and Mitigate darkweb risks
The Cyber Express
Cyber Security News and Magazine

Search

HostsExposed BucketsExposed Files

Resources

API DocumentationPlatform GuideODIN CLIPostmanSDKs
GoPythonJavaScript

Contact Us

[email protected]

Legal

Terms of ServiceSecurity Disclosure PolicyPrivacy Policy
Leading Threat Intelligence Company
LinkedInTwitter XYoutube
ODIN logoODIN logo
LinkedInGithubMediumTwitter XYoutube
Launch YC: Odin - Attack surface monitoring and internet scanning for everyone

Made with ❤️ from Cupertino

© 2025 Cyble Inc. All Rights Reserved.

217.78.171.154

SummaryCVE DetailsRaw Data
21 Jul 2025, 06:48:54 UTC
{
  "scan_id": 1752774106,
  "ip": "217.78.171.154",
  "is_ipv4": true,
  "is_ipv6": false,
  "location": {
    "network": "217.78.171.144/28",
    "postal_code": "73527",
    "coordinates": {
      "latitude": "48.8204",
      "longitude": "9.7801"
    },
    "geo_point": "48.8204, 9.7801",
    "locale_code": "en",
    "continent": "Europe",
    "country_code": "DE",
    "country_name": "Germany",
    "city": "Schwäbisch Gmünd"
  },
  "location_updated_at": "2025-07-18T16:53:20Z",
  "asn": {
    "number": "AS41998",
    "organization": "NetCom BW GmbH",
    "country_code": ""
  },
  "asn_updated_at": "0001-01-01T00:00:00Z",
  "whois": {
    "network": "217.78.160.0/20",
    "organization": "NetCom BW",
    "descr": "NetCom BW",
    "_encoding": {
      "raw": "BASE64"
    }
  },
  "whois_updated_at": "2024-12-09T08:53:34Z",
  "tags": [
    {
      "name": "is_anonymous_proxy",
      "pretty_name": "Anonymous Proxy",
      "value": false,
      "last_updated_at": "2025-07-18T16:53:20Z"
    },
    {
      "name": "is_cdn",
      "pretty_name": "CDN",
      "value": false,
      "last_updated_at": "2025-07-18T20:20:47Z"
    },
    {
      "name": "is_satellite_provider",
      "pretty_name": "Satellite Provider",
      "value": false,
      "last_updated_at": "2025-07-18T16:53:20Z"
    }
  ],
  "services": [
    {
      "port": 80,
      "protocol": "tcp",
      "name": "http",
      "version": "",
      "product": "squid",
      "extra_info": "",
      "tunnel": "",
      "modules": {
        "http": {
          "body_murmur": 1102184460,
          "body_sha256": "bfc2d90fec682a001e974784901efddaf43497428c20598cb36daf8496c58cd5",
          "content_length": 147943,
          "headers": {
            "connection": [
              "keep-alive"
            ],
            "content_length": [
              "147943"
            ],
            "content_type": [
              "text/html;charset=utf-8"
            ],
            "date": [
              "Wed, 16 Jul 2025 09:05:33 GMT"
            ],
            "server": [
              "squid"
            ],
            "unknown": [
              {
                "key": "mime_version",
                "value": [
                  "1.0"
                ]
              },
              {
                "key": "x_cache",
                "value": [
                  "MISS from firewall.mack-gmbh.de"
                ]
              },
              {
                "key": "x_squid_error",
                "value": [
                  "ERR_ACCESS_DENIED 0"
                ]
              }
            ],
            "via": [
              "1.1 firewall.mack-gmbh.de (squid)"
            ]
          },
          "protocol": "HTTP/1.1",
          "status_code": 403,
          "title": "ERROR: The requested URL could not be retrieved"
        }
      },
      "url": "http://217.78.171.154/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-07-16T09:05:35.276Z"
    },
    {
      "port": 443,
      "protocol": "tcp",
      "name": "https",
      "version": "",
      "product": "squid",
      "extra_info": "",
      "tunnel": "ssl",
      "modules": {
        "http": {
          "body_murmur": 1102184460,
          "body_sha256": "bfc2d90fec682a001e974784901efddaf43497428c20598cb36daf8496c58cd5",
          "content_length": 147945,
          "headers": {
            "connection": [
              "keep-alive"
            ],
            "content_length": [
              "147945"
            ],
            "content_type": [
              "text/html;charset=utf-8"
            ],
            "date": [
              "Mon, 21 Jul 2025 06:48:50 GMT"
            ],
            "server": [
              "squid"
            ],
            "unknown": [
              {
                "key": "x_cache",
                "value": [
                  "MISS from firewall.mack-gmbh.de"
                ]
              },
              {
                "key": "mime_version",
                "value": [
                  "1.0"
                ]
              },
              {
                "key": "x_squid_error",
                "value": [
                  "ERR_ACCESS_DENIED 0"
                ]
              }
            ],
            "via": [
              "1.1 firewall.mack-gmbh.de (squid)"
            ]
          },
          "protocol": "HTTP/1.1",
          "status_code": 403,
          "title": "ERROR: The requested URL could not be retrieved"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "authority_info_access": {
                "issuer_urls": [
                  "http://repository.certum.pl/dvcasha2.cer"
                ],
                "ocsp_urls": [
                  "http://dvcasha2.ocsp"
                ]
              },
              "authority_key_id": "e531adbf3a1196f483bc503cd4b7909b90eede25",
              "basic_constraints": {
                "is_ca": true
              },
              "certificate_policies": [
                {
                  "id": "2.23.140.1.2.1"
                },
                {
                  "cps": [
                    "https://www.certum.pl/CPS"
                  ],
                  "id": "1.2.616.1.113527.2.5.1.3"
                }
              ],
              "crl_distribution_points": [
                "http://crl.certum.pl/dvcasha2.crl"
              ],
              "extended_key_usage": {
                "any": false,
                "apple_code_signing": false,
                "apple_code_signing_development": false,
                "apple_code_signing_third_party": false,
                "apple_crypto_development_env": false,
                "apple_crypto_env": false,
                "apple_crypto_maintenance_env": false,
                "apple_crypto_production_env": false,
                "apple_crypto_qos": false,
                "apple_crypto_test_env": false,
                "apple_crypto_tier0_qos": false,
                "apple_crypto_tier1_qos": false,
                "apple_crypto_tier2_qos": false,
                "apple_crypto_tier3_qos": false,
                "apple_ichat_encryption": false,
                "apple_ichat_signing": false,
                "apple_resource_signing": false,
                "apple_software_update_signing": false,
                "apple_system_identity": false,
                "client_auth": true,
                "code_signing": false,
                "dvcs": false,
                "eap_over_lan": false,
                "eap_over_ppp": false,
                "email_protection": false,
                "ipsec_end_system": false,
                "ipsec_intermediate_system_usage": false,
                "ipsec_tunnel": false,
                "ipsec_user": false,
                "microsoft_ca_exchange": false,
                "microsoft_cert_trust_list_signing": false,
                "microsoft_csp_signature": false,
                "microsoft_document_signing": false,
                "microsoft_drm": false,
                "microsoft_drm_individualization": false,
                "microsoft_efs_recovery": false,
                "microsoft_embedded_nt_crypto": false,
                "microsoft_encrypted_file_system": false,
                "microsoft_enrollment_agent": false,
                "microsoft_kernel_mode_code_signing": false,
                "microsoft_key_recovery_21": false,
                "microsoft_key_recovery_3": false,
                "microsoft_license_server": false,
                "microsoft_licenses": false,
                "microsoft_lifetime_signing": false,
                "microsoft_mobile_device_software": false,
                "microsoft_nt5_crypto": false,
                "microsoft_oem_whql_crypto": false,
                "microsoft_qualified_subordinate": false,
                "microsoft_root_list_signer": false,
                "microsoft_server_gated_crypto": false,
                "microsoft_sgc_serialized": false,
                "microsoft_smart_display": false,
                "microsoft_smartcard_logon": false,
                "microsoft_system_health": false,
                "microsoft_system_health_loophole": false,
                "microsoft_timestamp_signing": false,
                "microsoft_whql_crypto": false,
                "netscape_server_gated_crypto": false,
                "ocsp_signing": false,
                "sbgp_cert_aa_service_auth": false,
                "server_auth": true,
                "time_stamping": false
              },
              "issuer_alt_name": {
                "email": [
                  "[email protected]"
                ]
              },
              "key_usage": {
                "certificate_sign": false,
                "content_commitment": false,
                "crl_sign": false,
                "data_encipherment": false,
                "decipher_only": false,
                "digital_signature": true,
                "encipher_only": false,
                "key_agreement": false,
                "key_encipherment": true
              },
              "subject_alt_name": {
                "dns_names": [
                  "*.mack-gmbh.de",
                  "mack-gmbh.de"
                ]
              },
              "subject_key_id": "a65a80edc637c841aabdf2b37a31b68e21749bca"
            },
            "fingerprint_md5": "F958A715A55916CB4868DF0E31658E7C",
            "fingerprint_sha1": "6402F0BE9A1DF4608971B8C33C9413BCB11333BD",
            "fingerprint_sha256": "0A7322FAF895789463C92D85F3CA5280A96B369C9B636E34136A4DEBCEA9AA6E",
            "issuer": {
              "common_name": [
                "Certum Domain Validation CA SHA2"
              ],
              "country": [
                "PL"
              ],
              "organization": [
                "Unizeto Technologies S.A."
              ],
              "organizational_unit": [
                "Certum Certification Authority"
              ]
            },
            "jarm": "2ad2ad16d2ad2ad00042d42d0000000b7957bea5dccaf2976e02aac6e2963a",
            "redacted": false,
            "revocation": {
              "crl": {
                "next_update": "2025-07-28T05:50:10",
                "reason": "UNKNOWN",
                "revoked": false
              },
              "ocsp": {
                "next_update": "2025-07-28T06:48:50",
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "107392942486671110264357609622830461825",
            "signature": {
              "algorithm": {
                "name": "SHA256-RSA",
                "oid": "1.2.840.113549.1.1.11"
              },
              "self_signed": false
            },
            "signed_certificate_timestamps": [
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "4e75a3275c9a10c3385b6cd4df3f52eb1df0e08e1b8d69c0b1fa64b1629a39df",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "3045022100c2b59e7864fa991d58d543ec425f174c35cc90204a2367b287ff3be401b3aea002203f98bd47c6cac43c221077eed856d384c81e20af02377c261258b9cccca05bd4"
                },
                "timestamp": "2024-05-22T15:00:36.344000",
                "version": "v1"
              },
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "a2e30ae445efbdad9b7e38ed47677753d7825b8494d72b5e1b2cc4b950a447e7",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "30440220348ae6415175d6250cd234ba0515c6c2f87fdc2a3a8524ca9fd6e88ccc21ddcd02205b397e703457ec276dc57e55c892da8f37370ef03020e1e70ecaa4abc846be39"
                },
                "timestamp": "2024-05-22T15:00:36.576000",
                "version": "v1"
              },
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "7d591e12e1782a7b1c61677c5efdf8d0875c14a04e959eb9032fd90e8c2e79b8",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "3046022100acaa6853ada7d21865232d261180d63acd90280f07b6587953d15279e26f55590221009af5754ef4228493e8addfc78e755330f26a653393365414b4a933359c63fb7b"
                },
                "timestamp": "2024-05-22T15:00:36.728000",
                "version": "v1"
              }
            ],
            "signed_certificate_timestamps_oid": "1.3.6.1.4.1.11129.2.4.2",
            "subject": {
              "common_name": [
                "*.mack-gmbh.de"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "*.mack-gmbh.de",
                "mack-gmbh.de"
              ],
              "extended_dns_names": [
                {
                  "domain": "mack-gmbh",
                  "fld": "mack-gmbh.de",
                  "subdomain": "*",
                  "tld": "de"
                },
                {
                  "domain": "mack-gmbh",
                  "fld": "mack-gmbh.de",
                  "tld": "de"
                }
              ]
            },
            "subject_key_info": {
              "_key": "rsa",
              "dh": [],
              "dsa": [],
              "ecdsa": [],
              "fingerprint_sha256": "6e469caf8c74bf1b43da538fe221ecb8ef8bbde7c2111c649953d959c33e5e0e",
              "key_algorithm": "RSA",
              "rsa": {
                "exponent": 65537,
                "length": 4096
              }
            },
            "tbs_fingerprint": "cf12d74d1757836ec5c58b9011b2a6dd2d57a9b9ee42e9b8df5cc54bde66fcd6",
            "tbs_noct_fingerprint": "2e1b97fa062f34b41a9865115953c07bbf8ce891ed54d183bb9133b2eef46b49",
            "validation_level": "DV",
            "validity": {
              "length_seconds": 34128000,
              "not_after": "2025-06-21T15:00:34",
              "not_before": "2024-05-22T15:00:35"
            },
            "version": 2
          },
          "fingerprint_sha256": "0A7322FAF895789463C92D85F3CA5280A96B369C9B636E34136A4DEBCEA9AA6E",
          "precert": false,
          "tags": [
            "dv",
            "trusted"
          ]
        }
      },
      "url": "https://217.78.171.154/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-07-21T06:48:54.426Z"
    },
    {
      "port": 6443,
      "protocol": "tcp",
      "name": "http",
      "version": "",
      "product": "Apache httpd",
      "extra_info": "",
      "tunnel": "ssl",
      "softwares": [
        {
          "uri": "cpe:/a:apache:http_server",
          "part": "a",
          "vendor": "apache",
          "product": "http_server",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "http": {
          "body_murmur": 418648025,
          "body_sha256": "49755d34dfa3043d485cc9585a6062daed4a7ee99f9dc68eb6e4ef14775e436a",
          "component": [
            "Apache HTTP Server",
            "Django",
            "Python"
          ],
          "content_length": 5906,
          "headers": {
            "cache_control": [
              "no-cache, no-store, must-revalidate, private"
            ],
            "content_language": [
              "en"
            ],
            "content_length": [
              "5906"
            ],
            "content_type": [
              "text/html; charset=utf-8"
            ],
            "date": [
              "Wed, 16 Jul 2025 22:13:20 GMT"
            ],
            "expires": [
              "Wed, 16 Jul 2025 22:13:20 GMT"
            ],
            "pragma": [
              "no-cache"
            ],
            "server": [
              "Apache"
            ],
            "set_cookie": [
              "csrftoken=2BlLKiArwAJCvZxoXG0ojTVTGUCtikYbLV39cyUIWo6EfBW9EU3fwgYfIvQzBGWk; expires=Wed, 15 Jul 2026 22:13:20 GMT; HttpOnly; Max-Age=31449600; Path=/; SameSite=Lax; Secure",
              "sessionid=778iqfgblhe5978wiigizakzp5v3pawv; HttpOnly; Path=/; SameSite=Lax; Secure"
            ],
            "strict_transport_security": [
              "max-age=15768000"
            ],
            "vary": [
              "Cookie,Accept-Language"
            ],
            "x_content_type_options": [
              "nosniff"
            ],
            "x_frame_options": [
              "sameorigin"
            ],
            "x_xss_protection": [
              "1; mode=block"
            ]
          },
          "protocol": "HTTP/1.1",
          "redirects": [
            {
              "location": "/wbm/login/",
              "status_code": 302,
              "status_line": "302 Found"
            }
          ],
          "status_code": 200,
          "title": "Logon - SINEMA Remote Connect"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "basic_constraints": {
                "is_ca": true
              },
              "extended_key_usage": {
                "any": false,
                "apple_code_signing": false,
                "apple_code_signing_development": false,
                "apple_code_signing_third_party": false,
                "apple_crypto_development_env": false,
                "apple_crypto_env": false,
                "apple_crypto_maintenance_env": false,
                "apple_crypto_production_env": false,
                "apple_crypto_qos": false,
                "apple_crypto_test_env": false,
                "apple_crypto_tier0_qos": false,
                "apple_crypto_tier1_qos": false,
                "apple_crypto_tier2_qos": false,
                "apple_crypto_tier3_qos": false,
                "apple_ichat_encryption": false,
                "apple_ichat_signing": false,
                "apple_resource_signing": false,
                "apple_software_update_signing": false,
                "apple_system_identity": false,
                "client_auth": false,
                "code_signing": false,
                "dvcs": false,
                "eap_over_lan": false,
                "eap_over_ppp": false,
                "email_protection": false,
                "ipsec_end_system": false,
                "ipsec_intermediate_system_usage": false,
                "ipsec_tunnel": false,
                "ipsec_user": false,
                "microsoft_ca_exchange": false,
                "microsoft_cert_trust_list_signing": false,
                "microsoft_csp_signature": false,
                "microsoft_document_signing": false,
                "microsoft_drm": false,
                "microsoft_drm_individualization": false,
                "microsoft_efs_recovery": false,
                "microsoft_embedded_nt_crypto": false,
                "microsoft_encrypted_file_system": false,
                "microsoft_enrollment_agent": false,
                "microsoft_kernel_mode_code_signing": false,
                "microsoft_key_recovery_21": false,
                "microsoft_key_recovery_3": false,
                "microsoft_license_server": false,
                "microsoft_licenses": false,
                "microsoft_lifetime_signing": false,
                "microsoft_mobile_device_software": false,
                "microsoft_nt5_crypto": false,
                "microsoft_oem_whql_crypto": false,
                "microsoft_qualified_subordinate": false,
                "microsoft_root_list_signer": false,
                "microsoft_server_gated_crypto": false,
                "microsoft_sgc_serialized": false,
                "microsoft_smart_display": false,
                "microsoft_smartcard_logon": false,
                "microsoft_system_health": false,
                "microsoft_system_health_loophole": false,
                "microsoft_timestamp_signing": false,
                "microsoft_whql_crypto": false,
                "netscape_server_gated_crypto": false,
                "ocsp_signing": false,
                "sbgp_cert_aa_service_auth": false,
                "server_auth": true,
                "time_stamping": false
              },
              "key_usage": {
                "certificate_sign": false,
                "content_commitment": false,
                "crl_sign": false,
                "data_encipherment": false,
                "decipher_only": false,
                "digital_signature": true,
                "encipher_only": false,
                "key_agreement": false,
                "key_encipherment": true
              },
              "subject_alt_name": {
                "ip_address": [
                  "212.184.213.106"
                ]
              }
            },
            "fingerprint_md5": "888BC91DA25598A035A4C8F9C0B5A039",
            "fingerprint_sha1": "1F1F8EF994DEFA1DD6E1875CAE013BCAFD0E2E60",
            "fingerprint_sha256": "58DF091EEDF4178BFD8D5827CB05C433E37D44A43AA34BCB91F8142D615409EC",
            "issuer": {
              "common_name": [
                "CA 000001 SINEMA RC"
              ]
            },
            "jarm": "16d16d16d14d16d00016d16d16d16df572ac71996ec56855731b41418b2c77",
            "redacted": false,
            "revocation": {
              "ocsp": {
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "5",
            "signature": {
              "algorithm": {
                "name": "SHA256-RSA",
                "oid": "1.2.840.113549.1.1.11"
              },
              "self_signed": false
            },
            "subject": {
              "common_name": [
                "192.168.128.200"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "192.168.128.200"
              ],
              "extended_dns_names": []
            },
            "subject_key_info": {
              "_key": "rsa",
              "dh": [],
              "dsa": [],
              "ecdsa": [],
              "fingerprint_sha256": "3bc7d8da55fdaaa65ec9388cb3ee094dbaaf3d82ef0accc7dc49329187bbf9bc",
              "key_algorithm": "RSA",
              "rsa": {
                "exponent": 65537,
                "length": 2048
              }
            },
            "tbs_fingerprint": "3349cc0caaaa1b2a73137d6cff1fc1dcf1a8a22ff8f903278f684b938422fd03",
            "validation_level": "DV",
            "validity": {
              "length_seconds": 315360000,
              "not_after": "2026-04-26T13:34:04",
              "not_before": "2016-04-28T13:34:04"
            },
            "version": 2
          },
          "fingerprint_sha256": "58DF091EEDF4178BFD8D5827CB05C433E37D44A43AA34BCB91F8142D615409EC",
          "precert": false,
          "tags": [
            "dv",
            "trusted"
          ]
        }
      },
      "cve": [
        {
          "id": "CVE-1999-0070",
          "severity": "medium"
        },
        {
          "id": "CVE-1999-1199",
          "severity": "high"
        },
        {
          "id": "CVE-2023-25690",
          "severity": "critical"
        }
      ],
      "url": "https://217.78.171.154:6443/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-07-17T11:53:57.533Z"
    }
  ],
  "services_hash": "650262efb1d6d73695aae9f07e5aeefe3b1a7f4287344170081e88d1cfbacd79",
  "last_updated_at": "2025-07-21T06:48:54.426Z",
  "banner": [
    "http",
    "tls"
  ],
  "is_vuln": true,
  "cveDetails": {
    "CVE-1999-0070": {
      "id": "CVE-1999-0070",
      "references": [
        "https://lists.apache.org/thread.html/rc5d27fc1e76dc5650e1a3f1db1de403120f4c2d041cb7352850455c2%40%3Cusers.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rc5d27fc1e76dc5650e1a3f1db1de403120f4c2d041cb7352850455c2%40%3Cusers.httpd.apache.org%3E"
      ],
      "score": 5,
      "services": [
        "6443/http"
      ],
      "severity": "medium",
      "summary": "test-cgi program allows an attacker to list files on the server.",
      "vector_string": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
      "weakness": "NVD-CWE-noinfo"
    },
    "CVE-1999-1199": {
      "id": "CVE-1999-1199",
      "references": [
        "http://marc.info/?l=bugtraq&m=90252779826784&w=2",
        "http://marc.info/?l=bugtraq&m=90276683825862&w=2",
        "http://marc.info/?l=bugtraq&m=90280517007869&w=2",
        "http://marc.info/?l=bugtraq&m=90286768232093&w=2",
        "http://www.redhat.com/support/errata/rh51-errata-general.html#apache",
        "https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E",
        "http://marc.info/?l=bugtraq&m=90252779826784&w=2",
        "http://marc.info/?l=bugtraq&m=90276683825862&w=2",
        "http://marc.info/?l=bugtraq&m=90280517007869&w=2",
        "http://marc.info/?l=bugtraq&m=90286768232093&w=2",
        "http://www.redhat.com/support/errata/rh51-errata-general.html#apache",
        "https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E"
      ],
      "score": 10,
      "services": [
        "6443/http"
      ],
      "severity": "high",
      "summary": "Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the \"sioux\" vulnerability.",
      "vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
      "weakness": "NVD-CWE-Other"
    },
    "CVE-2023-25690": {
      "id": "CVE-2023-25690",
      "references": [
        "http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html",
        "https://security.gentoo.org/glsa/202309-01",
        "http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html",
        "https://security.gentoo.org/glsa/202309-01"
      ],
      "score": 9.8,
      "services": [
        "6443/http"
      ],
      "severity": "critical",
      "summary": "Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.\n\n\n\n\nConfigurations are affected when mod_proxy is enabled along with some form of RewriteRule\n or ProxyPassMatch in which a non-specific pattern matches\n some portion of the user-supplied request-target (URL) data and is then\n re-inserted into the proxied request-target using variable \nsubstitution. For example, something like:\n\n\n\n\nRewriteEngine on\nRewriteRule \"^/here/(.*)\" \"http://example.com:8080/elsewhere?$1\"; [P]\nProxyPassReverse /here/ http://example.com:8080/\n\n\nRequest splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-444"
    },
    "CVE-2023-27522": {
      "id": "CVE-2023-27522",
      "references": [
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html",
        "https://security.gentoo.org/glsa/202309-01"
      ],
      "score": 7.5,
      "services": [
        "6443/http"
      ],
      "severity": "high",
      "summary": "HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.nnSpecial characters in the origin response header can truncate/split the response forwarded to the client.nnn",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "weakness": "CWE-444"
    }
  }
}