Описание
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
A flaw was found in Apache HTTP Server (httpd) versions 2.4.0 to 2.4.41. Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirected instead to an unexpected URL within the request URL.
Отчет
This issue only affects httpd versions between 2.4.0 and 2.4.41. Therefore Red Hat Enterprise Linux 5 and 6 are not affected by this flaw.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | httpd | Not affected | ||
Red Hat Enterprise Linux 6 | httpd | Not affected | ||
Red Hat JBoss Enterprise Web Server 2 | httpd | Not affected | ||
JBoss Core Services Apache HTTP Server 2.4.37 SP2 | httpd | Fixed | RHSA-2020:1336 | 06.04.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-apr | Fixed | RHSA-2020:1337 | 06.04.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-brotli | Fixed | RHSA-2020:1337 | 06.04.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd | Fixed | RHSA-2020:1337 | 06.04.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native | Fixed | RHSA-2020:1337 | 06.04.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_http2 | Fixed | RHSA-2020:1337 | 06.04.2020 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-openssl | Fixed | RHSA-2020:1337 | 06.04.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_r ...
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
Уязвимость функции mod_rewrite сервера приложений Apache Tomcat, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
EPSS
6.1 Medium
CVSS3