Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- >= 2.4.0, <= 2.4.65
A vulnerability exists in Apache HTTP Server versions 2.4.0 through 2.4.65, allowing environment variables set via the Apache configuration to unexpectedly override variables calculated by the server for CGI programs. This improper neutralization of escape, meta, or control sequences could lead to unintended behavior in CGI applications.
Exploitation of this vulnerability could cause CGI programs to behave unexpectedly, potentially leading to unauthorized actions or information disclosure.
Users are advised to upgrade to Apache HTTP Server version 2.4.66, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.