cbcvebase.
CVE-2017-15715
published 2018-03-26

CVE-2017-15715: In Apache httpd 2.4.0 to 2.4.29, the expression specified in could match '$' to a newline character in a malicious filename, rather than matching only the end…

high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
ITWEXPLOIT
Exploited in the wild
In Apache httpd 2.4.0 to 2.4.29, the expression specified in could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachehttp_server2.4.0 – 2.4.29
apache_software_foundationapache_http_server
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.4.33-1 (bookworm)apache2 2.4.33-1 (bookworm)
debiandebian_linux
debiandebian_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vulncheck8.1HIGH