Date: Wed, 14 Aug 2019 15:50:09 -0500 From: Daniel Ruggeri <druggeri@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2019-10098: mod_rewrite configurations vulnerable to open redirect CVE-2019-10098: mod_rewrite configurations vulnerable to open redirect Severity: Low Vendor: The Apache Software Foundation Versions Affected: httpd 2.4.0 to 2.4.39 Description: Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL. Mitigation: Anchor captures used as back-references, prefix self-referential redirects with / or scheme, host, and port. Credit: The issue was discovered by Yukitsugu Sasaki <yukitugu.sasaki@...il.com> References: https://httpd.apache.org/security/vulnerabilities_24.html
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.