Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10098

Опубликовано: 14 авг. 2019
Источник: redhat
CVSS3: 3.7
EPSS Высокий

Описание

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

A vulnerability was discovered in Apache httpd, in mod_rewrite. Certain self-referential mod_rewrite rules could be fooled by encoded newlines, causing them to redirect to an unexpected location. An attacker could abuse this flaw in a phishing attack or as part of a client-side attack on browsers.

Меры по смягчению последствий

This flaw requires the use of certain Rewrite configuration directives. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Rewrite' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5httpdOut of support scope
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat JBoss Enterprise Web Server 2httpdOut of support scope
Red Hat JBoss Enterprise Web Server 2httpd22Out of support scope
Red Hat JBoss Web Server 3httpd24Out of support scope
JBoss Core Services Apache HTTP Server 2.4.37 SP2httpdFixedRHSA-2020:133606.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-aprFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-brotliFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-httpdFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-mod_cluster-nativeFixedRHSA-2020:133706.04.2020

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1743959httpd: mod_rewrite potential open redirect

EPSS

Процентиль: 99%
0.81459
Высокий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

CVSS3: 6.1
nvd
больше 5 лет назад

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

CVSS3: 6.1
debian
больше 5 лет назад

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_r ...

CVSS3: 6.1
github
около 3 лет назад

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

CVSS3: 6.1
fstec
больше 5 лет назад

Уязвимость функции mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации или оказать воздействие на целостность информации

EPSS

Процентиль: 99%
0.81459
Высокий

3.7 Low

CVSS3