CVE-2020-1927
02.04.2020, 00:15
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.0 ≤ 𝑥 ≤ 2.4.41 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 20.04 |
| opensuse | leap | 15.1 |
| netapp | oncommand_unified_manager_core_package | - |
| broadcom | brocade_fabric_operating_system | - |
| oracle | communications_element_manager | 8.1.1 |
| oracle | communications_element_manager | 8.2.0 |
| oracle | communications_element_manager | 8.2.1 |
| oracle | communications_session_report_manager | 8.1.1 |
| oracle | communications_session_report_manager | 8.2.0 |
| oracle | communications_session_report_manager | 8.2.1 |
| oracle | communications_session_route_manager | 8.1.1 |
| oracle | communications_session_route_manager | 8.2.0 |
| oracle | communications_session_route_manager | 8.2.1 |
| oracle | enterprise_manager_ops_center | 12.4.0.0 |
| oracle | instantis_enterprisetrack | 17.1 ≤ 𝑥 ≤ 17.3 |
| oracle | sd-wan_aware | 8.2 |
| oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
|
Common Weakness Enumeration
References