Описание
A flaw was found in Apache HTTP Server. An attacker could achieve unintended code execution when an internal redirect generated by a Common Gateway Interface (CGI) program points to a non-executable file. If the target file resides in a directory configured for CGI execution and lacks a file extension recognized by the MIME handler, the server incorrectly treats and executes the target file as a script. This issue could allow an attacker to run unauthorized commands or code within the server context.
Меры по смягчению последствий
If CGI functionality is not required, disable CGI execution by commenting out mod_cgi or mod_cgid in the Apache configuration (for example, in /etc/httpd/conf.modules.d/01-cgi.conf), or by removing ExecCGI from Options directives in /etc/httpd/conf/httpd.conf.
Apply the changes to the running service:
systemctl reload httpd
Caveats: Disabling CGI modules or execution options will prevent any existing CGI applications from functioning.
Warning: Reloading or restarting the httpd service may temporarily disrupt active connections.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | httpd | Fix deferred | ||
| Red Hat Enterprise Linux 6 | httpd | Not affected | ||
| Red Hat Enterprise Linux 7 | httpd | Not affected | ||
| Red Hat Enterprise Linux 8 | httpd:2.4/httpd | Not affected | ||
| Red Hat Enterprise Linux 9 | httpd | Fix deferred | ||
| Red Hat Hardened Images | httpd-main-2.4.69-1.hum1 | Fixed | RHSA-2026:74858 | 02.10.2026 |
Показывать по
Дополнительная информация
Статус:
3.7 Low
CVSS3
Связанные уязвимости
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
Deployment of wrong handler vulnerability in Apache HTTP Server allows ...
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
3.7 Low
CVSS3