mod_perl: arbitrary Perl code execution in the context of the user account via a user-owned .htaccess
Published Aug 26, 2018
9.8
CRITICALCVSS 3.0
EPSS 8.95%
Description
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
Affected products
- Vendor n/a Product Mod Perl 2.0 Through 2.0.10 Defaultn/a
- Version mod_perl 2.0 through 2.0.10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Mod Perl 2.0 Through 2.0.10 | n/a |
|
Configuration 2
- 8.0
Configuration 3
- 6.0
- 6.7
- 7.0
- 7.3
- 7.4
- 7.5
- 7.6
- 6.0
- 6.0
- 6.0
Configuration 4
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
No data.
Red Hat Enterprise Linux 6
mod_perl-0:2.0.4-12.el6_10
Fixed · RHSA-2018:2737
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-perl524-mod_perl-0:2.0.9-10.el6
Fixed · RHSA-2018:2826
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-perl524-mod_perl-0:2.0.9-10.el6
Fixed · RHSA-2018:2826
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-perl524-mod_perl-0:2.0.9-10.el7
Fixed · RHSA-2018:2826
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-perl526-mod_perl-0:2.0.10-10.el7
Fixed · RHSA-2018:2825
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-perl524-mod_perl-0:2.0.9-10.el7
Fixed · RHSA-2018:2826
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-perl526-mod_perl-0:2.0.10-10.el7
Fixed · RHSA-2018:2825
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-perl524-mod_perl-0:2.0.9-10.el7
Fixed · RHSA-2018:2826
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-perl526-mod_perl-0:2.0.10-10.el7
Fixed · RHSA-2018:2825
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-perl524-mod_perl-0:2.0.9-10.el7
Fixed · RHSA-2018:2826
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-perl526-mod_perl-0:2.0.10-10.el7
Fixed · RHSA-2018:2825
Red Hat Enterprise Linux 5
mod_perl
Will not fix
Red Hat Enterprise Linux 8
mod_perl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | mod_perl-0:2.0.4-12.el6_10 | Fixed | RHSA-2018:2737 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-perl524-mod_perl-0:2.0.9-10.el6 | Fixed | RHSA-2018:2826 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-perl524-mod_perl-0:2.0.9-10.el6 | Fixed | RHSA-2018:2826 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-perl524-mod_perl-0:2.0.9-10.el7 | Fixed | RHSA-2018:2826 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-perl526-mod_perl-0:2.0.10-10.el7 | Fixed | RHSA-2018:2825 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-perl524-mod_perl-0:2.0.9-10.el7 | Fixed | RHSA-2018:2826 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-perl526-mod_perl-0:2.0.10-10.el7 | Fixed | RHSA-2018:2825 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-perl524-mod_perl-0:2.0.9-10.el7 | Fixed | RHSA-2018:2826 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-perl526-mod_perl-0:2.0.10-10.el7 | Fixed | RHSA-2018:2825 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-perl524-mod_perl-0:2.0.9-10.el7 | Fixed | RHSA-2018:2826 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-perl526-mod_perl-0:2.0.10-10.el7 | Fixed | RHSA-2018:2825 |
| Red Hat Enterprise Linux 5 | mod_perl | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | mod_perl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The default configurations shipped in Red Hat Enterprise Linux 6 and Red Hat Software Collections are not vulnerable to to this flaw. The UserDir option needs to be enabled as well as AllowOverride being set to values other than "None" for this to potentially pose a threat.
Red Hat mitigation
Disabling the UserDir directive and also setting AllowOverride None should prevent the processing of perl in user .htaccess files.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.95% (0.08946) | 95.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.95% (0.08946) | 94.56th | v5 (v2026.06.15) |
| Mar 12, 2026 | 3.45% (0.03454) | 87.34th | v4 (v2025.03.14) |
| Dec 22, 2025 | 4.61% (0.04609) | 88.88th | v4 (v2025.03.14) |
| Dec 14, 2025 | 3.07% (0.03070) | 86.30th | v4 (v2025.03.14) |
| Jul 30, 2025 | 4.88% (0.04879) | 89.16th | v4 (v2025.03.14) |
| Jul 13, 2025 | 6.22% (0.06221) | 90.44th | v4 (v2025.03.14) |
| Apr 16, 2025 | 4.05% (0.04048) | 87.85th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.33% (0.06334) | 90.03th | v4 (v2025.03.14) |
| Mar 29, 2025 | 15.27% (0.15265) | 91.06th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.33% (0.06334) | 90.28th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.10% (0.02097) | 89.57th | v3 (v2023.03.01) |
| Jul 5, 2024 | 1.51% (0.01506) | 87.06th | v3 (v2023.03.01) |
| Feb 26, 2024 | 0.76% (0.00758) | 80.56th | v3 (v2023.03.01) |
| Jan 17, 2024 | 1.00% (0.00998) | 81.95th | v3 (v2023.03.01) |
| Aug 20, 2023 | 0.83% (0.00833) | 79.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.71% (0.00713) | 77.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.77% (0.04771) | 89.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.77% (0.04771) | 88.16th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.77% (0.04771) | 74.54th | v2 (v2022.01.01) |
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00063.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00065.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/105195 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2737 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2825 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2826 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2011-2767 Vendor Advisory
- https://bugs.debian.org/644169 x_refsource_MISCIssue TrackingMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1623265 Issue Tracking
- https://lists.apache.org/thread.html/c8ebe8aad147a3ad2e7b0e8b2da45263171ab5d0fc7f8c100feaa94d%40%3Cmodperl-cvs.perl.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2018/09/msg00018.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://mail-archives.apache.org/mod_mbox/perl-modperl/201110.mbox/raw/%3C20111004084343.GA21290%40ktnx.net%3E x_refsource_MISCMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-2767
- https://usn.ubuntu.com/3825-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3825-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2011-2767
Change history (0)
No recorded changes yet.