Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-65082

Опубликовано: 05 дек. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.

This issue affects Apache HTTP Server from 2.4.0 through 2.4.65.

Users are recommended to upgrade to version 2.4.66 which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Версия от 2.4.0 (включая) до 2.4.66 (исключая)

EPSS

Процентиль: 33%
0.00128
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 6.5
ubuntu
12 дней назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

msrc
9 дней назад

Apache HTTP Server: CGI environment variable override

CVSS3: 6.5
debian
12 дней назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

CVSS3: 6.5
github
12 дней назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
fstec
около 1 месяца назад

Уязвимость веб-сервера Apache HTTP Server, связанная с непринятием мер по нейтрализации специальных управляющих элементов, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 33%
0.00128
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-150