9.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD
Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Affected (81)
Products: Resf: Rocky Linux · Redhat: Enterprise Linux Eus, Enterprise Linux For Arm 64, Enterprise Linux For Arm 64 Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Ibm Z Systems Eus S390x, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux For Scientific Computing, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Enterprise Linux Update Services For Sap Solutions, Enterprise Linux Workstation, Jboss Core Services, Software Collections · Apache: Http Server · +8 more
Show all products
Resf: Rocky Linux · Redhat: Enterprise Linux Eus, Enterprise Linux For Arm 64, Enterprise Linux For Arm 64 Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Ibm Z Systems Eus S390x, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux For Scientific Computing, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Enterprise Linux Update Services For Sap Solutions, Enterprise Linux Workstation, Jboss Core Services, Software Collections · Apache: Http Server · Fedoraproject: Fedora · Debian: Debian Linux · Broadcom: Brocade Fabric Operating System Firmware · Netapp: Cloud Backup, Clustered Data Ontap, Storagegrid · F5: F5os · Oracle: Enterprise Manager Ops Center, Http Server, Instantis Enterprisetrack, Secure Global Desktop, Zfs Storage Appliance Kit · Siemens: Ruggedcom Nms, Sinec Nms, Sinema Remote Connect Server, Sinema Server · Tenable: Tenable.sc
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.1 | |
| Version 8.0 | |
| Version 8.6 | |
| Version 7.0_s390x | |
| Version 8.1 | |
| Version 8.2 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.1 | |
| Version 7.0 | |
| Version 7.2 | |
| Version 7.6 | |
| Version 7.6 | |
| Version 7.6 | |
| Version 8.1 | |
| Version 7.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 7.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux Server | Version 7.0 |
Redhat Enterprise Linux Server Workstation | Version 7.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.4.48 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.4.0.0 | |
| Version 12.2.1.3.0 | |
| Version 17.1 | |
| Version 5.6 | |
| Version 8.8 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Before 1.0.3 | |
| Before 3.1 | |
| Version 14.0 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.19.1 |
References (39)
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing List
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Release Notes
Source: security@apache.org
Release Notes
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Broken LinkThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.