Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1927

Опубликовано: 01 апр. 2020
Источник: redhat
CVSS3: 6.1
EPSS Средний

Описание

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

A flaw was found in Apache HTTP Server (httpd) versions 2.4.0 to 2.4.41. Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirected instead to an unexpected URL within the request URL.

Отчет

This issue only affects httpd versions between 2.4.0 and 2.4.41. Therefore Red Hat Enterprise Linux 5 and 6 are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5httpdNot affected
Red Hat Enterprise Linux 6httpdNot affected
Red Hat JBoss Enterprise Web Server 2httpdNot affected
JBoss Core Services Apache HTTP Server 2.4.37 SP2httpdFixedRHSA-2020:133606.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-aprFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-brotliFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-httpdFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-mod_cluster-nativeFixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-mod_http2FixedRHSA-2020:133706.04.2020
JBoss Core Services on RHEL 6jbcs-httpd24-opensslFixedRHSA-2020:133706.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1820761httpd: mod_rewrite configurations vulnerable to open redirect

EPSS

Процентиль: 94%
0.15489
Средний

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
nvd
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
debian
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_r ...

CVSS3: 6.1
github
около 3 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
fstec
больше 5 лет назад

Уязвимость функции mod_rewrite сервера приложений Apache Tomcat, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 94%
0.15489
Средний

6.1 Medium

CVSS3