Record summary

CVE-2019-10098 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 22, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Apache HTTP Server

CVE List2.4.0 to 2.4.39affected

Proofs of concept

1

Catalogued exploits

ExploitDBApache Httpd mod_rewrite - Open RedirectsExploitDB exploitby Sebastian NeefNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMApache HTTP server v2.4.0 to v2.4.39 - Open RedirectCVSS 6.1

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.

Remediation

Upgrade Apache HTTP server to version 2.4.40 or later to mitigate this vulnerability.

WeaknessesCWE-601
Authorsctflearner
Template tagscvecve2019redirectapacheservervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:apache:http_server"
Shodan: apache 2.4.49

Source: ProjectDiscovery

References

Showing 12 of 29