CVE-2017-15715

Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 26 Mar 2018, 15:00
Last modified:17 Sept 2024, 02:21

Vulnerability Summary

Overall Risk (default)
high
51/100
CVSS Score
8.1 HIGH
v3.0 (nvd)
EPSS Score
93.62% CRITICAL
94% probability -0.40%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Mar 2018, 15:00
Published
Vulnerability first disclosed
17 Sept 2024, 02:21
Last Modified
Vulnerability information updated

Description

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

CVSS Metrics

  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 93.62% Percentile: 100%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Affected Systems

  • apache software foundationapache http server

    2.4.0 to 2.4.29

  • UnknownHTTP Server

    ≥ 2.4.0, ≤ 2.4.29

  • canonicalubuntu_linux

    14.04 | 16.04 | 17.10 | 18.04

  • debiandebian_linux

    8.0 | 9.0

  • netappclustered_data_ontap

    na

  • netappsantricity_cloud_connector

    na

  • netappstorage_automation_store

    na

  • netappstoragegrid

    na

  • redhatenterprise_linux

    6.0 | 7.0 | 7.4 | 7.5 | 7.6

References (27)