Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-1927

Опубликовано: 02 апр. 2020
Источник: debian
EPSS Средний

Описание

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.43-1package
apache2ignoredjessiepackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-1927

  • https://svn.apache.org/r1873905

  • https://svn.apache.org/r1874191

EPSS

Процентиль: 94%
0.15489
Средний

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
redhat
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
nvd
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
github
около 3 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
fstec
больше 5 лет назад

Уязвимость функции mod_rewrite сервера приложений Apache Tomcat, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 94%
0.15489
Средний