Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1927

Опубликовано: 02 апр. 2020
Источник: ubuntu
Приоритет: low
CVSS2: 5.8
CVSS3: 6.1

Описание

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

РелизСтатусПримечание
bionic

released

2.4.29-1ubuntu4.14
devel

not-affected

2.4.43-1ubuntu1
eoan

ignored

end of life
esm-infra-legacy/trusty

needed

esm-infra/bionic

not-affected

2.4.29-1ubuntu4.14
esm-infra/focal

not-affected

2.4.41-4ubuntu3.1
esm-infra/xenial

not-affected

2.4.18-2ubuntu3.17
focal

released

2.4.41-4ubuntu3.1
groovy

not-affected

2.4.43-1ubuntu1
hirsute

not-affected

2.4.43-1ubuntu1

Показывать по

5.8 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
nvd
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
debian
около 5 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_r ...

CVSS3: 6.1
github
около 3 лет назад

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS3: 6.1
fstec
больше 5 лет назад

Уязвимость функции mod_rewrite сервера приложений Apache Tomcat, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

5.8 Medium

CVSS2

6.1 Medium

CVSS3

Уязвимость CVE-2020-1927