Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- >= 2.4.0, <= 2.4.67
A vulnerability in Apache HTTP Server in versions through 2.4.67 allows local authors of .htaccess files to read files with the privileges of the httpd user. This issue arises from improper privilege management, enabling unauthorized access to certain files.
Exploitation of this vulnerability could lead to unauthorized file access, allowing .htaccess authors to read files with elevated privileges.
Users are advised to upgrade to Apache HTTP Server version 2.4.68, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.