PT-2019-3893 · Apache+7 · Apache Http Server+7

Publicado

2019-07-09

·

Atualizado

2025-09-29

·

CVE-2019-10092

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.39
Description A limited cross-site scripting issue was reported affecting the mod proxy error page in Apache HTTP Server. This issue could allow an attacker to cause the link on the error page to be malformed, pointing to a page of their choice, but only where a server was set up with proxying enabled and misconfigured to display the Proxy Error page. The vulnerability is related to the failure to protect the structure of web pages, which could allow a remote attacker to redirect users to a malicious site using a specially crafted web page.
Recommendations For Apache HTTP Server versions 2.4.0 through 2.4.39, consider disabling the mod proxy module until a patch is available to prevent exploitation of the limited cross-site scripting issue in the mod proxy error page. Restrict access to the mod proxy error page to minimize the risk of exploitation. As a temporary workaround, ensure proper configuration of proxying to avoid displaying the Proxy Error page.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2019_2925
ALSA-2020:4751
ALSA-2020_4751
ALSA-2025_16880
ALT-PU-2019-2471
ALT-PU-2019-3402
BDU:2019-04286
CESA-2020_4751
CVE-2019-10092
DLA-1900-1
DLA-1900-2
DSA-4509-1
DSA-4509-2
DSA-4509-3
ELSA-2020-4751
MGASA-2019-0407
OPENSUSE-SU-2019:2051-1
OPENSUSE-SU-2019_2051-1
OPENSUSE-SU-2024:10623-1
RHSA-2019:4126
RHSA-2020:1337
RHSA-2020:4751
RHSA-2020_4751
RLSA-2020:4751
RLSA-2020_4751
SUSE-SU-2019:2237-1
SUSE-SU-2019:2329-1
SUSE-SU-2019_2237-1
SUSE-SU-2019_2329-1
SUSE-SU-2021:0779-1
SUSE-SU-2021:2004-1
SUSE-SU-2021_0779-1
SUSE-SU-2021_2004-1
USN-4113-1
USN-4113-2

Produtos afetados

Alt Linux
Almalinux
Apache Http Server
Centos
Red Hat
Rocky Linux
Suse
Ubuntu