Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd=… directives.
This issue affects Apache HTTP Server before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Http_server | Apache | * | 2.4.66 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | httpd-0:2.4.63-4.el10_1.3 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | httpd-0:2.4.63-1.el10_0.3 | * |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | RedHat | httpd-0:2.2.15-71.el6_10.2 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | httpd-0:2.4.6-99.el7_9.7 | * |
| Red Hat Enterprise Linux 8 | RedHat | httpd:2.4-8100020251212173309.489197e6 | * |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | httpd:2.4-8020020251223095446.4cda2c84 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | httpd:2.4-8040020251223095736.522a0ee4 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | httpd:2.4-8040020251223095736.522a0ee4 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | httpd:2.4-8060020251223095927.ad008a3a | * |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | httpd:2.4-8060020251223095927.ad008a3a | * |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | httpd:2.4-8060020251223095927.ad008a3a | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | httpd:2.4-8080020251223093308.63b34585 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | httpd:2.4-8080020251223093308.63b34585 | * |
| Red Hat Enterprise Linux 9 | RedHat | httpd-0:2.4.62-7.el9_7.3 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | httpd-0:2.4.51-7.el9_0.11 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | httpd-0:2.4.53-11.el9_2.14 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | httpd-0:2.4.57-11.el9_4.4 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | httpd-0:2.4.62-4.el9_6.5 | * |
| Apache2 | Ubuntu | upstream | * |