Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-38474

Опубликовано: 01 июл. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

РелизСтатусПримечание
devel

released

2.4.62-1ubuntu1
esm-infra-legacy/trusty

released

2.4.7-1ubuntu4.22+esm10
esm-infra/bionic

released

2.4.29-1ubuntu4.27+esm4
esm-infra/focal

not-affected

2.4.41-4ubuntu3.23
esm-infra/xenial

released

2.4.18-2ubuntu3.17+esm14
focal

released

2.4.41-4ubuntu3.23
jammy

released

2.4.52-1ubuntu4.14
mantic

released

2.4.57-2ubuntu2.5
noble

released

2.4.58-1ubuntu8.6
oracular

released

2.4.62-1ubuntu1.1

Показывать по

EPSS

Процентиль: 68%
0.00594
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
около 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
nvd
около 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
debian
около 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.5 ...

CVSS3: 9.8
github
около 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость функции mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 68%
0.00594
Низкий

9.8 Critical

CVSS3