Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-29170

Опубликовано: 08 июн. 2026
Источник: debian

Описание

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.68-1package
apache2fixed2.4.68-1~deb13u1trixiepackage
apache2fixed2.4.68-1~deb12u1bookwormpackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29170

  • Fixed by: https://github.com/apache/httpd/commit/e86bf540f166b3a322f7e7f9cd4aad4cd44deee6 (trunk)

  • Fixed by: https://github.com/apache/httpd/commit/04641bce75a2734ad8150f9a6bc84fc5205e852b (2.4.68-rc1-candidate)

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 5.4
redhat
3 месяца назад

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 6.1
nvd
3 месяца назад

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

msrc
3 месяца назад

Apache HTTP Server: mod_proxy_ftp XSS

CVSS3: 6.1
redos
около 2 месяцев назад

Уязвимость httpd