CVE-2020-1927

Advisory lineage Upstream: 0 Downstream: 16
Modified
Published: 01 Apr 2020, 23:08
Last modified:04 Aug 2024, 06:53

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.1 MEDIUM
v3.1 (nvd)
EPSS Score
4.95% LOW
5% probability -6.35%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Apr 2020, 23:08
Published
Vulnerability first disclosed
04 Aug 2024, 06:53
Last Modified
Vulnerability information updated

Description

In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 4.95% Percentile: 90%

Techniques & Countermeasures

  • CWE-601URL Redirection to Untrusted Site ('Open Redirect')

    The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Affected Systems

  • apacheapache_http_server

    2.4.0 to 2.4.41

  • UnknownHTTP Server

    ≥ 2.4.0, ≤ 2.4.41

  • broadcombrocade_fabric_operating_system

    na

  • canonicalubuntu_linux

    16.04 | 18.04 | 20.04

  • debiandebian_linux

    9.0 | 10.0

  • fedoraprojectfedora

    31 | 32

  • netapponcommand_unified_manager_core_package

    na

  • opensuseleap

    15.1

  • oraclecommunications_element_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_session_report_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_session_route_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oracleenterprise_manager_ops_center

    12.4.0.0

  • oracleinstantis_enterprisetrack

    ≥ 17.1, ≤ 17.3

  • oraclesd-wan_aware

    8.2

  • oraclezfs_storage_appliance_kit

    8.8

References (27)