Lucene search

K
freebsdFreeBSD088B8B7D-446C-11EF-B611-84A93843EB75
HistoryJul 17, 2024 - 12:00 a.m.

Apache httpd -- Source code disclosure with handlers configured via AddType

2024-07-1700:00:00
vuxml.freebsd.org
27
apache httpd
source code disclosure
addtype
configuration
handlers
cve-2024-40725
http server 2.4.61
content-type
php
unix

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

38.6%

The Apache httpd project reports:

source code disclosure with handlers configured via AddType
(CVE-2024-40725) (Important): A partial fix for CVE-2024-39884
in the core of Apache HTTP Server 2.4.61 ignores some use of the
legacy content-type based configuration of handlers. “AddType”
and similar configuration, under some circumstances where files
are requested indirectly, result in source code disclosure of
local content. For example, PHP scripts may be served instead
of interpreted.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchapache24= 2.4.60UNKNOWN
FreeBSDanynoarchapache24< 2.4.62UNKNOWN

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

38.6%