Lucene search

K
redosRedosROS-20240812-15
HistoryAug 12, 2024 - 12:00 a.m.

ROS-20240812-15

2024-08-1200:00:00
redos.red-soft.ru
4
apache http server
vulnerabilities
outdated configuration
insufficient checking
incoming requests
unauthorized access
ssrf attacks

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

38.6%

Apache HTTP Server kernel vulnerability is related to ignoring outdated configuration of the
of handlers by the “AddType” function. Exploitation of the vulnerability could allow an attacker acting remotely to disclose protected information.
remotely to disclose protected information

Vulnerability in Apache HTTP Server kernel is related to the use of outdated handler configuration.
of handlers. Exploitation of the vulnerability could allow an attacker acting remotely to gain
unauthorized access to protected information

Vulnerability in mod_rewrite module of Apache HTTP Server is related to insufficient checking of incoming requests.
of incoming requests. Exploitation of the vulnerability could allow a remote attacker to launch an SSRF attack,
launch an SSRF attack

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64httpd< 2.4.62-1UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

38.6%