Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

ubuntu логотип

CVE-2026-28808

6 месяцев назад

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-28808

6 месяцев назад

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 before OTP 28.4.2, OTP 27.3.4.10 and OTP 26.2.5.19, corresponding to inets from 5.10 before 9.6.2, 9.3.2.4 and 9.1.0.6.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-28808

6 месяцев назад

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2026-28808

4 месяца назад

ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)

EPSS: Низкий
debian логотип

CVE-2026-28808

6 месяцев назад

Incorrect Authorization vulnerability in Erlang OTP (inets modules) al ...

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2026-12071

6 месяцев назад

Уязвимость языка программирования Erlang, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к конфиденциальным данным и оказать влияние на их целостность

CVSS3: 7.4
EPSS: Низкий
redos логотип

ROS-20260907-80-0081

16 дней назад

Уязвимость erlang

CVSS3: 7.4
EPSS: Низкий
redos логотип

ROS-20260907-73-0050

16 дней назад

Уязвимость erlang

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1714-1

5 месяцев назад

Security update for erlang

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2010-1

4 месяца назад

Security update for erlang26

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20607-1

5 месяцев назад

Security update for erlang

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-28808

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS3: 9.8
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-28808

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 before OTP 28.4.2, OTP 27.3.4.10 and OTP 26.2.5.19, corresponding to inets from 5.10 before 9.6.2, 9.3.2.4 and 9.1.0.6.

CVSS3: 7.4
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-28808

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS3: 9.8
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2026-28808

ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)

1%
Низкий
4 месяца назад
debian логотип
CVE-2026-28808

Incorrect Authorization vulnerability in Erlang OTP (inets modules) al ...

CVSS3: 9.8
1%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-12071

Уязвимость языка программирования Erlang, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к конфиденциальным данным и оказать влияние на их целостность

CVSS3: 7.4
1%
Низкий
6 месяцев назад
redos логотип
ROS-20260907-80-0081

Уязвимость erlang

CVSS3: 7.4
1%
Низкий
16 дней назад
redos логотип
ROS-20260907-73-0050

Уязвимость erlang

CVSS3: 7.4
1%
Низкий
16 дней назад
suse-cvrf логотип
SUSE-SU-2026:1714-1

Security update for erlang

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2010-1

Security update for erlang26

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20607-1

Security update for erlang

5 месяцев назад

Уязвимостей на страницу