Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10092

Опубликовано: 14 авг. 2019
Источник: redhat
CVSS3: 4.7
EPSS Высокий

Описание

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

A cross-site scripting vulnerability was found in Apache httpd, affecting the mod_proxy error page. Under certain circumstances, a crafted link could inject content into the HTML displayed in the error page, potentially leading to client-side exploitation.

Меры по смягчению последствий

This flaw is only exploitable if Proxy* directives are used in Apache httpd configuration. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Proxy' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_proxy.html

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5httpdOut of support scope
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdAffected
Red Hat JBoss Enterprise Web Server 2httpdOut of support scope
Red Hat JBoss Enterprise Web Server 2httpd22Out of support scope
Red Hat JBoss Web Server 3httpd24Out of support scope
JBoss Core Services Apache HTTP Server 2.4.37 SP2httpdFixedRHSA-2020:133606.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-aprFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-brotliFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-httpdFixedRHSA-2020:133706.04.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1743956httpd: limited cross-site scripting in mod_proxy error page

EPSS

Процентиль: 99%
0.8415
Высокий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

CVSS3: 6.1
nvd
больше 5 лет назад

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

CVSS3: 6.1
debian
больше 5 лет назад

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting iss ...

suse-cvrf
больше 4 лет назад

Security update for apache2

github
около 3 лет назад

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

EPSS

Процентиль: 99%
0.8415
Высокий

4.7 Medium

CVSS3