6.1

CVE-2019-10092

Exploit

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 2.4.0 <= 2.4.39
OpensuseLeap Version15.0
OpensuseLeap Version15.1
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
RedhatSoftware Collection Version1.0
FedoraprojectFedora Version30
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version19.04
NetappClustered Data Ontap Version <= 9.5
NetappClustered Data Ontap Version9.6 Update-
NetappClustered Data Ontap Version9.6 Updatep1
NetappClustered Data Ontap Version9.6 Updatep3
NetappClustered Data Ontap Version9.6 Updatep4
NetappClustered Data Ontap Version9.6 Updatep7
NetappClustered Data Ontap Version9.6 Updatep8
OracleSecure Global Desktop Version5.4
OracleSecure Global Desktop Version5.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 82.38% 0.992
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://usn.ubuntu.com/4113-1/
Patch
Third Party Advisory
https://seclists.org/bugtraq/2019/Aug/47
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Oct/24
Third Party Advisory
Mailing List