CVE-2004-2343Apache Http Server vulnerability

4 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.2%
top 62.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web access, and a local user already has the privileges to perform the same operations without using ErrorDocument

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDapache/http_server2.0.47

🔴Vulnerability Details

2
GHSA
GHSA-r2gf-vgv9-wfwv: ** DISPUTED ** Apache HTTP Server 22022-04-29
CVEList
CVE-2004-2343: Apache HTTP Server 22005-08-16

📋Vendor Advisories

1
Red Hat
CVE-2004-2343: Apache HTTP Server 2
CVE-2004-2343 — Apache Http Server vulnerability | cvebase