Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-768g-4qpg-32w7

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.

This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.

Users are recommended to upgrade to version 2.4.66 which fixes the issue.

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.

This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.

Users are recommended to upgrade to version 2.4.66 which fixes the issue.

EPSS

Процентиль: 36%
0.00149
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
nvd
2 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
msrc
около 2 месяцев назад

Apache HTTP Server: CGI environment variable override

CVSS3: 6.5
debian
2 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость веб-сервера Apache HTTP Server, связанная с непринятием мер по нейтрализации специальных управляющих элементов, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 36%
0.00149
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-150