Back

MEDIUM

httpd: mod_rewrite potential open redirect

Published Sep 25, 2019

Description

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

Affected products

Remediation

Red Hat mitigation

This flaw requires the use of certain Rewrite configuration directives. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Rewrite' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html

Metrics

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 25, 2019
Updated Aug 4, 2024
Reserved Mar 26, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 14, 2019