漏洞信息详情
Apache HTTP Server 安全漏洞
漏洞简介
Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。
Apache HTTP Server 2.4.17 至 2.4.48 版本存在安全漏洞,该漏洞可通过HTTP/2发送的精心制作的方法绕过身份验证,并由mod_proxy转发。
漏洞公告
目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:https://github.com/apache/
参考网址
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T/
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210917-0004/
来源:http2
链接:http2
来源:MISC
链接:https://portswigger.net/research/
来源:CONFIRM
链接:https://www.tenable.com/security/tns-2021-17
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG/
来源:httpd
链接:httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patch
来源:MISC
链接:https://github.com/apache/
来源:httpd.apache.org%3E
链接:httpd.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70@%3Ccvs.
来源:MLIST
链接:https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d@%3Ccvs.
来源:CISCO
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164318/Ubuntu-Security-Notice-USN-5090-3.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.4004.3
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.4004.2
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3229
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3239
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2985
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092301
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6492615
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3387
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101513
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101922
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164329/Ubuntu-Security-Notice-USN-5090-4.html
来源:httpd-2.4.49-VWL69sWQ
链接:httpd-2.4.49-VWL69sWQ
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3148
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021091317
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021091707
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3482
受影响实体
暂无
补丁
暂无
还没有评论,来说两句吧...