Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-38474

Опубликовано: 01 июл. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 9.8

Описание

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

РелизСтатусПримечание
devel

released

2.4.62-1ubuntu1
esm-infra-legacy/trusty

released

2.4.7-1ubuntu4.22+esm10
esm-infra/bionic

released

2.4.29-1ubuntu4.27+esm4
esm-infra/focal

released

2.4.41-4ubuntu3.23
esm-infra/xenial

released

2.4.18-2ubuntu3.17+esm14
focal

released

2.4.41-4ubuntu3.23
jammy

released

2.4.52-1ubuntu4.16
mantic

released

2.4.57-2ubuntu2.5
noble

released

2.4.58-1ubuntu8.8
oracular

released

2.4.62-1ubuntu1.1

Показывать по

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
nvd
больше 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
debian
больше 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.5 ...

CVSS3: 9.8
github
больше 1 года назад

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.

CVSS3: 9.8
fstec
больше 1 года назад

Уязвимость функции mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

9.8 Critical

CVSS3

Уязвимость CVE-2024-38474