ZeroHour

CVE-2017-15715

CVSS 3.0
8.1 high
EPSS
85%p100
Published
()
Modified
Description

In Apache httpd 2.4.0 to 2.4.29, the expression specified in could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

Vendors
apachedebiancanonicalnetappredhat
Products
http server, debian linux, ubuntu linux, santricity cloud connector, storage automation store, storagegrid, clustered data ontap, enterprise linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.