Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-0220

Опубликовано: 01 апр. 2019
Источник: redhat
CVSS3: 3.3
EPSS Средний

Описание

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

Отчет

Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This flaw has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

This flaw can be mitigation by replacing multiple consecutive slashes, used in directives that match against the path component of the request URL with regular expressions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5httpdOut of support scope
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat JBoss Enterprise Web Server 2httpdOut of support scope
Red Hat Virtualization 4rhvm-applianceNot affected
JBoss Core Services on RHEL 6jbcs-httpd24-aprFixedRHSA-2020:025027.01.2020
JBoss Core Services on RHEL 6jbcs-httpd24-apr-utilFixedRHSA-2020:025027.01.2020
JBoss Core Services on RHEL 6jbcs-httpd24-brotliFixedRHSA-2020:025027.01.2020
JBoss Core Services on RHEL 6jbcs-httpd24-curlFixedRHSA-2020:025027.01.2020
JBoss Core Services on RHEL 6jbcs-httpd24-httpdFixedRHSA-2020:025027.01.2020
JBoss Core Services on RHEL 6jbcs-httpd24-janssonFixedRHSA-2020:025027.01.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-41
https://bugzilla.redhat.com/show_bug.cgi?id=1695036httpd: URL normalization inconsistency

EPSS

Процентиль: 95%
0.20573
Средний

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

CVSS3: 5.3
nvd
больше 6 лет назад

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

CVSS3: 5.3
debian
больше 6 лет назад

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When ...

CVSS3: 5.3
github
больше 3 лет назад

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость модуля RewriteRule веб-сервера Apache, связанная с использованием имени с неправильной ссылкой, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 95%
0.20573
Средний

3.3 Low

CVSS3