Description
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1900-1 | apache2 security update |
Debian DSA |
DSA-4509-1 | apache2 security update |
Ubuntu USN |
USN-4113-1 | Apache HTTP Server vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T22:10:09.765Z
Reserved: 2019-03-26T00:00:00.000Z
Link: CVE-2019-10098
No data.
Status : Modified
Published: 2019-09-25T17:15:10.353
Modified: 2026-06-17T02:10:13.870
Link: CVE-2019-10098
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Debian DLA
Debian DSA
Ubuntu USN