CVE-2019-10098

MEDIUM EXPLOITED NUCLEI

Apache HTTP Server <2.4.40 - SSRF

Title source: llm

Description

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

Exploits (1)

exploitdb WORKING POC
by Sebastian Neef · webappsmultiple
https://www.exploit-db.com/exploits/47689

Nuclei Templates (1)

Apache HTTP server v2.4.0 to v2.4.39 - Open Redirect
MEDIUMby ctflearner
Shodan: cpe:"cpe:2.3:a:apache:http_server" || apache 2.4.49

References (17)

Scores

CVSS v3 6.1
EPSS 0.8031
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

VulnCheck KEV 2022-02-22
CWE
CWE-601
Status published
Products (1)
apache/http_server 2.4.0 - 2.4.39
Published Sep 25, 2019
Tracked Since Feb 18, 2026