ZeroHour

CVE-2019-0220

CVSS 3.0
5.3 medium
EPSS
18%p97
Published
()
Modified
Description

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

Vendors
apacheopensusedebianfedoraprojectcanonical
Products
http server, leap, debian linux, fedora, ubuntu linux
Weakness
CWE-706
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.