Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92ww-hwmg-qq7p

Опубликовано: 08 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

EPSS

Процентиль: 94%
0.13047
Средний

8.2 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 3 лет назад

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVSS3: 7.1
redhat
больше 3 лет назад

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVSS3: 8.2
nvd
больше 3 лет назад

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVSS3: 8.2
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 8.2
debian
больше 3 лет назад

A crafted URI sent to httpd configured as a forward proxy (ProxyReques ...

EPSS

Процентиль: 94%
0.13047
Средний

8.2 High

CVSS3

Дефекты

CWE-476