CVE-2020-25073: Medium severity debian freedombox vulnerability
FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a local connection. This affects both the freedombox and plinth packages of some Linux distributions, but only if the Apache modstatus module is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25073?
CVE-2020-25073 is considered a high severity vulnerability as it allows remote attackers to access sensitive information from the Apache HTTP Server's /server-status page.
How do I fix CVE-2020-25073?
To fix CVE-2020-25073, users should upgrade to Freedombox version 20.14 or later, which addresses this security issue.
What are the potential impacts of CVE-2020-25073?
The potential impacts of CVE-2020-25073 include unauthorized access to sensitive data which could lead to further exploitation of the system.
Which versions of Freedombox are affected by CVE-2020-25073?
CVE-2020-25073 affects Freedombox versions up to and including 20.13.
Can CVE-2020-25073 be exploited remotely?
Yes, CVE-2020-25073 can be exploited remotely by attackers who manage to connect through a Tor onion service or PageKite.