CVE-2019-10098
Summary
| CVE | CVE-2019-10098 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-25 17:15:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Apache |
Http Server |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296074 Oracle Solaris 11.4 Support Repository Update (SRU) 22.69.4 Missing (CPUAPR2020)
- 376188 F5 BIG-IP Local Traffic Manager (LTM), Application Security Manager (ASM), Access Policy Manager (APM) Apache HTTPD Vulnerability (K25126370)
- 376862 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (964768)
- 377378 Alibaba Cloud Linux Security Update for httpd:2.4 (ALINUX3-SA-2022:0017)
- 377516 Alibaba Cloud Linux Security Update for httpd (ALINUX2-SA-2020:0165)
- 500018 Alpine Linux Security Update for apache2
- 503709 Alpine Linux Security Update for apache2
- 710128 Gentoo Linux Apache Multiple vulnerabilities (GLSA 201909-04)
- 940248 AlmaLinux Security Update for httpd:2.4 (ALSA-2020:4751)
- 960434 Rocky Linux Security Update for httpd:2.4 (RLSA-2020:4751)