Impact
The vulnerability arises internal redirect to a file located inside a directory marked as executable by mod_cgi but the file lacks an extension treated as CGI by mod_mime. The server incorrectly processes this target as CGI and executes it, allowing an attacker to run arbitrary code. The flaw is a form of limited remote code execution, confined to internal redirects to files in CGI directories.
Affected Systems
Apache HTTP Server versions 2.4.60 through 2.4.68 are affected. No other Apache products or versions are listed.
Risk and Exploitability
The flaw is exploitable by an attacker who can control the arguments to a CGI program that performs an internal redirect. Because the target file must already exist in a CGI-enabled directory and have no mod_mime mapping, the attack surface is narrow but still permits arbitrary code execution. The CVSS score is not supplied, and EPSS data is unavailable, so the current exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV. The most likely attack vector is an internal redirect from a CGI script to a non-CGI file in a CGI directory.
OpenCVE Enrichment