Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29170

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A flaw was found in Apache HTTP Server, specifically within the mod_proxy_ftp module. This cross-site scripting (XSS) vulnerability occurs during the generation of HTML directory lists when the server is configured to list FTP directory contents via either a forward or reverse proxy. An attacker could exploit this by injecting malicious scripts into web pages, which could lead to information disclosure or unauthorized actions when viewed by other users.

Отчет

This Moderate impact cross-site scripting (XSS) vulnerability in Apache HTTP Server's mod_proxy_ftp module requires specific server configurations to be exploitable. The flaw occurs when mod_proxy_ftp is enabled and configured to list FTP directory contents via a proxy, which is not a default setup in Red Hat Enterprise Linux. Successful exploitation depends on a user viewing a specially crafted web page, potentially leading to information disclosure or unauthorized actions within the user's browser context.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10httpdFix deferred
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat Enterprise Linux 8httpdFix deferred
Red Hat Enterprise Linux 9httpdFix deferred
Red Hat Hardened Imageshttpd-main-2.4.68-1.hum1FixedRHSA-2026:2504210.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2486419httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation

EPSS

Процентиль: 41%
0.00523
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 месяцев назад

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 6.1
nvd
около 2 месяцев назад

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

msrc
около 1 месяца назад

Apache HTTP Server: mod_proxy_ftp XSS

CVSS3: 6.1
debian
около 2 месяцев назад

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML di ...

CVSS3: 6.1
github
около 2 месяцев назад

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

EPSS

Процентиль: 41%
0.00523
Низкий

5.4 Medium

CVSS3