QID 150402
Date Published: 2021-12-02
QID 150402: Apache HTTP Server Unexpected URL matching (CVE-2021-30641)
The Apache HTTP Server, colloquially called Apache, is a free and open-source cross-platform web server software.
On affected versions of Apache HTTP Server a Unexpected URL matching behavior vulnerability exists when directive MergeSlashes has been set to "OFF" in the configuration file.
Affected Versions:
Apache HTTP Server version 2.4.39
Apache HTTP Server version 2.4.41
Apache HTTP Server version 2.4.43
Apache HTTP Server version 2.4.46
QID Detection Logic:(Unauthenticated)
This QID sends a HTTP GET request and checks the response headers to confirm if the host is running vulnerable version of Apache HTTP Server.
Successful exploitation of this vulnerability would allow a remote attacker to bypass implemented security restrictions on the target server.
- Apache HTTP Server Security Advisory -
httpd.apache.org/security/vulnerabilities_24.html
CVEs related to QID 150402
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache HTTP Server |
|