Количество 30
Количество 30
ELSA-2025-14997
ELSA-2025-14997: httpd security update (MODERATE)
RLSA-2025:15095
Moderate: httpd security update
RLSA-2025:15023
Moderate: httpd security update
ELSA-2025-15095
ELSA-2025-15095: httpd security update (MODERATE)
ELSA-2025-15023
ELSA-2025-15023: httpd security update (MODERATE)
RLSA-2025:15123
Moderate: httpd:2.4 security update
ELSA-2025-15123
ELSA-2025-15123: httpd:2.4 security update (MODERATE)
SUSE-SU-2025:02685-1
Security update for apache2
SUSE-SU-2025:02684-1
Security update for apache2
SUSE-SU-2025:02683-1
Security update for apache2
SUSE-SU-2025:02682-1
Security update for apache2
SUSE-SU-2025:02565-1
Security update for apache2
openSUSE-SU-2026:20810-1
Security update for apache2
CVE-2024-47252
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.
CVE-2024-47252
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.
CVE-2024-47252
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.
CVE-2024-47252
Apache HTTP Server: mod_ssl error log variable escaping
CVE-2024-47252
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP ...
CVE-2025-49812
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
CVE-2025-49812
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2025-14997 ELSA-2025-14997: httpd security update (MODERATE) | 10 месяцев назад | |||
RLSA-2025:15095 Moderate: httpd security update | 10 месяцев назад | |||
RLSA-2025:15023 Moderate: httpd security update | 10 месяцев назад | |||
ELSA-2025-15095 ELSA-2025-15095: httpd security update (MODERATE) | 11 месяцев назад | |||
ELSA-2025-15023 ELSA-2025-15023: httpd security update (MODERATE) | 11 месяцев назад | |||
RLSA-2025:15123 Moderate: httpd:2.4 security update | 11 месяцев назад | |||
ELSA-2025-15123 ELSA-2025-15123: httpd:2.4 security update (MODERATE) | 11 месяцев назад | |||
SUSE-SU-2025:02685-1 Security update for apache2 | 12 месяцев назад | |||
SUSE-SU-2025:02684-1 Security update for apache2 | 12 месяцев назад | |||
SUSE-SU-2025:02683-1 Security update for apache2 | 12 месяцев назад | |||
SUSE-SU-2025:02682-1 Security update for apache2 | 12 месяцев назад | |||
SUSE-SU-2025:02565-1 Security update for apache2 | около 1 года назад | |||
openSUSE-SU-2026:20810-1 Security update for apache2 | 2 месяца назад | |||
CVE-2024-47252 Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2024-47252 Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2024-47252 Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2024-47252 Apache HTTP Server: mod_ssl error log variable escaping | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2024-47252 Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP ... | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2025-49812 In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade. | CVSS3: 7.4 | 1% Низкий | около 1 года назад | |
CVE-2025-49812 In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade. | CVSS3: 7.5 | 1% Низкий | около 1 года назад |
Уязвимостей на страницу