Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-38474

Опубликовано: 01 июл. 2024
Источник: nvd
CVSS3: 9.8
CVSS3: 8.1
EPSS Низкий

Описание

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.

Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Версия от 2.4.0 (включая) до 2.4.60 (исключая)
Конфигурация 2
cpe:2.3:o:netapp:clustered_data_ontap:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00764
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 месяцев назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
redhat
12 месяцев назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
debian
12 месяцев назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.5 ...

CVSS3: 9.8
github
12 месяцев назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
fstec
12 месяцев назад

Уязвимость функции mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 72%
0.00764
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-116