CVE-2020-25073
Summary
| CVE | CVE-2020-25073 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-02 02:15:00 UTC |
| Updated | 2020-09-11 16:20:00 UTC |
| Description | FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a local connection. This affects both the freedombox and plinth packages of some Linux distributions, but only if the Apache mod_status module is enabled. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Debian |
Freedombox |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| apache: /server-status page publicly visible through Tor or Pagekite (#1935) · Issues · FreedomBox / FreedomBox · GitLab |
MISC |
salsa.debian.org |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180698 Debian Security Update for plinth (CVE-2020-25073)