Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- 2.4.64
A vulnerability in Apache HTTP Server in version 2.4.64 causes all 'RewriteCond expr ...' evaluations to incorrectly assess as 'true'. This flaw can disrupt expected behavior in configurations relying on conditional rewrites, potentially leading to unintended URL processing or access control bypasses. The issue is fixed in version 2.4.65.
Exploitation of this vulnerability could lead to incorrect URL rewriting, causing access control bypasses or unintended resource exposure.
Users are advised to upgrade to Apache HTTP Server version 2.4.65, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.