CVE-2020-1927

MEDIUM6.1EPSS 4.9%

apache2 - security update

發布日:2020/4/2修改日:2025/4/3
也稱為:ALPINE-CVE-2020-1927BIT-apache-2020-1927DEBIAN-CVE-2020-1927

描述

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

參考連結(30)