REDHAT-BUG-2419365: High severity Apache HTTP Server vulnerability
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and modcgid (but not modcgi) passes the shell-escaped query string to #exec cmd="..." directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2419365?
The severity of REDHAT-BUG-2419365 is high due to the potential for remote code execution via malicious shell-escaped queries.
How do I fix REDHAT-BUG-2419365?
To fix REDHAT-BUG-2419365, you should upgrade Apache HTTP Server to version 2.4.66 or later.
Which versions of Apache HTTP Server are affected by REDHAT-BUG-2419365?
Apache HTTP Server versions 2.4.65 and earlier are affected by REDHAT-BUG-2419365.
What components are involved in REDHAT-BUG-2419365?
REDHAT-BUG-2419365 involves the Server Side Includes (SSI) feature with mod_cgid enabled.
Is REDHAT-BUG-2419365 a critical vulnerability?
Yes, REDHAT-BUG-2419365 is considered critical as it can allow execution of arbitrary commands on the server.