CVE-2019-10098explotación observadaCWE-601

CVE-2019-10098: fallo en Apache HTTP Server

Publicada el · Actualizada el

82Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actepss 74%
de la publicación al arma19 días
Publicada en NVD25 sept
1ª PoC+19d
VulnCheck+881d
probabilidad de explotación
74%top 1% de las CVE
explotación observada
síVulnCheck
1 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
4 productos (12 componentes)
Red Hat Enterprise Linux 6 · Red Hat JBoss Enterprise Web Server 2 · Red Hat Enterprise Linux 5 · Red Hat JBoss Web Server 3
workaround: This flaw requires the use of certain Rewrite configuration directives. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Rewrite' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html
Corregido
16 productos (409 componentes)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) · Red Hat JBoss Core Services on RHEL 6 Server · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) · y otros 11
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.
Productos afectados
n/a · Apache HTTP Server
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.