VYPR

rpm package

suse/apache2&distro=SUSE Linux Enterprise Server 12 SP5

pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Vulnerabilities (45)

  • CVE-2020-11985MedAug 7, 2020
    affected < 2.4.23-29.63.1fixed 2.4.23-29.63.1

    IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but

  • CVE-2020-1927MedApr 2, 2020
    affected < 2.4.23-29.54.1fixed 2.4.23-29.54.1

    In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

  • CVE-2020-1934MedApr 1, 2020
    affected < 2.4.23-29.54.1fixed 2.4.23-29.54.1

    In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

  • CVE-2020-1938CriKEVFeb 24, 2020
    affected < 2.4.23-29.54.1fixed 2.4.23-29.54.1

    When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exp

  • CVE-2019-10092MedSep 26, 2019
    affected < 2.4.23-29.69.1fixed 2.4.23-29.69.1

    In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server

Page 3 of 3