ZeroHour

CVE-2020-1927

CVSS 3.1
6.1 medium
EPSS
57%p99
Published
()
Modified
Description

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

Vendors
apachefedoraprojectdebiancanonicalopensusenetappbroadcomoracle
Products
http server, fedora, debian linux, ubuntu linux, leap, oncommand unified manager core package, brocade fabric operating system, communications element manager, communications session report manager, communications session route manager, enterprise manager ops center, instantis enterprisetrack
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.