Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-768g-4qpg-32w7

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.

This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.

Users are recommended to upgrade to version 2.4.66 which fixes the issue.

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.

This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.

Users are recommended to upgrade to version 2.4.66 which fixes the issue.

EPSS

Процентиль: 36%
0.00156
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
redhat
4 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
nvd
4 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
msrc
4 месяца назад

Apache HTTP Server: CGI environment variable override

CVSS3: 6.5
debian
4 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

EPSS

Процентиль: 36%
0.00156
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-150