REDHAT-BUG-2486416: Medium severity Apache HTTP Server vulnerability
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTTP Server: from through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2486416?
The severity of REDHAT-BUG-2486416 is classified as medium (4).
How do I fix REDHAT-BUG-2486416?
To fix REDHAT-BUG-2486416, upgrade to Apache HTTP Server version 2.4.68 or later.
What does REDHAT-BUG-2486416 affect?
REDHAT-BUG-2486416 affects Apache HTTP Server versions up to and including 2.4.67.
What type of vulnerability is REDHAT-BUG-2486416?
REDHAT-BUG-2486416 is classified as an Improper Privilege Management vulnerability.
Who is impacted by REDHAT-BUG-2486416?
Users who utilize local .htaccess files in Apache HTTP Server versions up to 2.4.67 are impacted by REDHAT-BUG-2486416.