Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-65082

Опубликовано: 05 дек. 2025
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 6.5

Описание

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

РелизСтатусПримечание
devel

released

2.4.66-2ubuntu1
esm-infra-legacy/trusty

released

2.4.7-1ubuntu4.22+esm12
esm-infra-legacy/xenial

released

2.4.18-2ubuntu3.17+esm17
esm-infra/bionic

released

2.4.29-1ubuntu4.27+esm7
esm-infra/focal

released

2.4.41-4ubuntu3.23+esm3
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

2.4.52-1ubuntu4.18
noble

released

2.4.58-1ubuntu8.10
plucky

ignored

end of life, was needs-triage
questing

released

2.4.64-1ubuntu3.2

Показывать по

EPSS

Процентиль: 53%
0.00789
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
8 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
nvd
8 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
msrc
8 месяцев назад

Apache HTTP Server: CGI environment variable override

CVSS3: 6.5
debian
8 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

CVSS3: 6.5
github
8 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

EPSS

Процентиль: 53%
0.00789
Низкий

6.5 Medium

CVSS3