Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-54090

Опубликовано: 23 июл. 2025
Источник: debian
EPSS Низкий

Описание

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.65-1package
apache2not-affectedbookwormpackage
apache2not-affectedbullseyepackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2025-54090

  • Fixed by: https://github.com/apache/httpd/commit/8abb3d06b23975705ebcf4bf4476464fd0b9bd0b (2.4.65)

  • Introduced by: https://github.com/apache/httpd/commit/8efe8ea18c6f7123c5779bb4d9551ccf407dc0c4 (2.4.64)

EPSS

Процентиль: 27%
0.00095
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 месяца назад

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

CVSS3: 4.8
redhat
около 1 месяца назад

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

CVSS3: 6.3
nvd
около 1 месяца назад

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

CVSS3: 6.3
msrc
22 дня назад

Описание отсутствует

CVSS3: 6.3
github
около 1 месяца назад

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

EPSS

Процентиль: 27%
0.00095
Низкий