Lucene search

K
cvelistApacheCVELIST:CVE-2019-0220
HistoryJun 11, 2019 - 8:49 p.m.

CVE-2019-0220

2019-06-1120:49:50
apache
www.cve.org
6

AI Score

6.5

Confidence

High

EPSS

0.007

Percentile

80.9%

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes (‘/’), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

CNA Affected

[
  {
    "product": "Apache HTTP Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "2.4.0 to 2.4.38"
      }
    ]
  }
]

References