![]() |
|
Apache 2.4.49 - Path Traversal Vulnerability - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: Hacking (https://sinister.ly/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking) +--- Thread: Apache 2.4.49 - Path Traversal Vulnerability (/Thread-Apache-2-4-49-Path-Traversal-Vulnerability) |
Apache 2.4.49 - Path Traversal Vulnerability - Oni - 10-08-2021 RE: Apache 2.4.49 - Path Traversal Vulnerability - fritz - 10-08-2021 (10-08-2021, 03:51 AM)Oni Wrote: I see several people out-of-date.You mean several people too much up-to-date right? This issue only affects Apache 2.4.49 and not earlier versions, although it seems it hasn't been published yet for most package manager (2.4.48-3.1 is the one on Debian stable apt). RE: Apache 2.4.49 - Path Traversal Vulnerability - ConcernedCitizen - 10-08-2021 Interesting. The vulnerable version was released on September 15th 2021, but luckily it had not yet been included in any major Linux distribution repositories (Ubuntu, for example, is still at 2.4.41). According to Shodan, 112,000 active deployments of the affected version are on the public internet, compared to the 1,719,000 total active Apache installations. Additional information available in NVD/NIST: CVE-2021-41773 |