CVE-2019-10092
published 2019-09-26CVE-2019-10092: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on…
PriorityP356medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
81.47%
99.6th percentile
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.4.0 – 2.4.39 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.4.41-1 (bookworm) | apache2 2.4.41-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| netapp | clustered_data_ontap | <= 9.5 | — |
| netapp | clustered_data_ontap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | secure_global_desktop | — | — |
| oracle | secure_global_desktop | — | — |
| redhat | software_collection | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·Exploit is only possible when the server has proxying enabled AND is misconfigured such that the Proxy Error page is displayed to clients. ↗
- ·The following httpd configuration pattern (ProxyPass/ProxyPassReverse with permissive access controls) is required to reproduce the vulnerable behavior. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_oracle4.7MEDIUM
vendor_ubuntu4.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Virtualization Risk Matrix: Web Server (Apache HTTPD Server) — CVE-2019-10092
vendor_oracle·2020-01-15·CVSS 4.7
CVE-2019-10092 [MEDIUM] Oracle Oracle Virtualization Risk Matrix: Web Server (Apache HTTPD Server) — CVE-2019-10092
Oracle Oracle Virtualization Risk Matrix: Web Server (Apache HTTPD Server) vulnerability
CVE: CVE-2019-10092
CVSS: 4.7
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2019-09-17·CVSS 4.2
[MEDIUM] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-4113-1 introduced a regression in Apache.
USN-4113-1 fixed vulnerabilities in the Apache HTTP server.
Unfortunately, that update introduced a regression when proxying
balancer manager connections in some configurations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Stefan Eissing discovered that the HTTP/2 implementation in Apache
did not properly handle upgrade requests from HTTP/1.1 to HTTP/2 in
some situations. A remote attacker could use this to cause a denial
of service (daemon crash). This issue only affected Ubuntu 18.04 LTS
and Ubuntu 19.04. (CVE-2019-0197)
Craig Young discovered that a memory overwrite error existed in
Apache when performing HTTP/2 very early pushes in some situ
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2019-08-29·CVSS 4.2
CVE-2019-0197 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache.
Stefan Eissing discovered that the HTTP/2 implementation in Apache
did not properly handle upgrade requests from HTTP/1.1 to HTTP/2 in
some situations. A remote attacker could use this to cause a denial
of service (daemon crash). This issue only affected Ubuntu 18.04 LTS
and Ubuntu 19.04. (CVE-2019-0197)
Craig Young discovered that a memory overwrite error existed in
Apache when performing HTTP/2 very early pushes in some situations. A
remote attacker could use this to cause a denial of service (daemon
crash). This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04.
(CVE-2019-10081)
Craig Young discovered that a read-after-free error existed in the
HTTP/2 implementation in Apache during
Red Hat
httpd: limited cross-site scripting in mod_proxy error page
vendor_redhat·2019-08-14·CVSS 6.1
CVE-2019-10092 [MEDIUM] CWE-79 httpd: limited cross-site scripting in mod_proxy error page
httpd: limited cross-site scripting in mod_proxy error page
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
A cross-site scripting vulnerability was found in Apache httpd, affecting the mod_proxy error page. Under certain circumstances, a crafted link could inject content into the HTML displayed in the error page, potentially leading to client-side exploitation.
Mitigation: This flaw is only exploitable if Proxy* directives are used in Apache httpd co
Debian
CVE-2019-10092: apache2 - In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was rep...
vendor_debian·2019·CVSS 6.1
CVE-2019-10092 [MEDIUM] CVE-2019-10092: apache2 - In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was rep...
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
Scope: local
bookworm: resolved (fixed in 2.4.41-1)
bullseye: resolved (fixed in 2.4.41-1)
forky: resolved (fixed in 2.4.41-1)
sid: resolved (fixed in 2.4.41-1)
trixie: resolved (fixed in 2.4.41-1)
GHSA
GHSA-qrr6-fpf4-x3v4: In Apache HTTP Server 2
ghsa_unreviewed·2022-05-24
CVE-2019-10092 [MEDIUM] CWE-79 GHSA-qrr6-fpf4-x3v4: In Apache HTTP Server 2
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
OSV
CVE-2019-10092: In Apache HTTP Server 2
osv·2019-09-26·CVSS 6.1
CVE-2019-10092 [MEDIUM] CVE-2019-10092: In Apache HTTP Server 2
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
OSV
apache2 regression
osv·2019-09-17·CVSS 4.2
[MEDIUM] apache2 regression
apache2 regression
USN-4113-1 fixed vulnerabilities in the Apache HTTP server.
Unfortunately, that update introduced a regression when proxying
balancer manager connections in some configurations. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Stefan Eissing discovered that the HTTP/2 implementation in Apache
did not properly handle upgrade requests from HTTP/1.1 to HTTP/2 in
some situations. A remote attacker could use this to cause a denial
of service (daemon crash). This issue only affected Ubuntu 18.04 LTS
and Ubuntu 19.04. (CVE-2019-0197)
Craig Young discovered that a memory overwrite error existed in
Apache when performing HTTP/2 very early pushes in some situations. A
remote attacker could use this to cause a denial of service (dae
OSV
apache2 vulnerabilities
osv·2019-08-29·CVSS 4.2
CVE-2019-0197 [MEDIUM] apache2 vulnerabilities
apache2 vulnerabilities
Stefan Eissing discovered that the HTTP/2 implementation in Apache
did not properly handle upgrade requests from HTTP/1.1 to HTTP/2 in
some situations. A remote attacker could use this to cause a denial
of service (daemon crash). This issue only affected Ubuntu 18.04 LTS
and Ubuntu 19.04. (CVE-2019-0197)
Craig Young discovered that a memory overwrite error existed in
Apache when performing HTTP/2 very early pushes in some situations. A
remote attacker could use this to cause a denial of service (daemon
crash). This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04.
(CVE-2019-10081)
Craig Young discovered that a read-after-free error existed in the
HTTP/2 implementation in Apache during connection shutdown. A remote
attacker could use this to possibly cause a
No detection rules found.
Exploit-DB
Apache Httpd mod_proxy - Error Page Cross-Site Scripting
exploitdb·2019-10-14
CVE-2019-10092 Apache Httpd mod_proxy - Error Page Cross-Site Scripting
Apache Httpd mod_proxy - Error Page Cross-Site Scripting
---
The trick is to use a vertical tab (`%09`) and then place another URL in the tag. So once a victim clicks the link on the error page, she will go somewhere else.
As you can see, the browser changes the destination from relative / to an absolute url https://enoflag.de. The exploit is `http://domain.tld/%09//otherdomain.tld`
Here's the httpd configuration to reproduce the behavior:
```
ProxyPass http://127.0.0.1:9000/ connectiontimeout=1 timeout=2
ProxyPassReverse http://127.0.0.1:9000/
Order allow,deny
Allow from all
```
Nuclei
Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2019-10092 [MEDIUM] Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting
Apache HTTP Server "
# digest: 4a0a00473045022100bdd9565965861eb202b7e2bbf2a3c07c99c66478ec3d9d3334492226e2f111960220179a30e44ced5eaff533057e2ba291437ec3bad514fa87ff23813b6135d1246b:922c64590222798bb761d5b6d8e72950
Bugzilla
CVE-2019-10092 httpd: limited cross-site scripting in mod_proxy error page
bugzilla·2019-08-21·CVSS 6.1
CVE-2019-10092 [MEDIUM] CVE-2019-10092 httpd: limited cross-site scripting in mod_proxy error page
CVE-2019-10092 httpd: limited cross-site scripting in mod_proxy error page
A limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malfomed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 1743957]
---
External References:
https://httpd.apache.org/security/vulnerabilities_24.html
---
This vulnerability is out of security support scope for the following product:
* Red Hat JBoss Web Server 3
* Red Hat JBoss Enterprise Web Server 2
Please refer to https://access.redhat
Bugzilla
CVE-2019-10092 httpd: limited cross-site scripting in mod_proxy error page [fedora-all]
bugzilla·2019-08-21·CVSS 6.1
CVE-2019-10092 [MEDIUM] CVE-2019-10092 httpd: limited cross-site scripting in mod_proxy error page [fedora-all]
CVE-2019-10092 httpd: limited cross-site scripting in mod_proxy error page [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.htmlhttp://www.openwall.com/lists/oss-security/2019/08/15/4http://www.openwall.com/lists/oss-security/2020/08/08/1http://www.openwall.com/lists/oss-security/2020/08/08/9https://access.redhat.com/errata/RHSA-2019:4126https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-10092-Limited%20Cross-Site%20Scripting%20in%20mod_proxy%20Error%20Page-Apache%20httpdhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/73768e31e0fcae03e12f5aa87da1cb26dece39327f3c32060baa3e94%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0a83b112cd9701ef8a2061c8ed557f3dc9bb774d4da69fbb91bbc3c4%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/08/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7RVHJHTU4JN3ULCQ44F2G6LZBF2LGNTC/https://seclists.org/bugtraq/2019/Aug/47https://seclists.org/bugtraq/2019/Oct/24https://security.gentoo.org/glsa/201909-04https://security.netapp.com/advisory/ntap-20190905-0003/https://support.f5.com/csp/article/K30442259https://usn.ubuntu.com/4113-1/https://www.debian.org/security/2019/dsa-4509https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.htmlhttp://www.openwall.com/lists/oss-security/2019/08/15/4http://www.openwall.com/lists/oss-security/2020/08/08/1http://www.openwall.com/lists/oss-security/2020/08/08/9https://access.redhat.com/errata/RHSA-2019:4126https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-10092-Limited%20Cross-Site%20Scripting%20in%20mod_proxy%20Error%20Page-Apache%20httpdhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/73768e31e0fcae03e12f5aa87da1cb26dece39327f3c32060baa3e94%40%3Cannounce.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0a83b112cd9701ef8a2061c8ed557f3dc9bb774d4da69fbb91bbc3c4%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/08/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/09/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7RVHJHTU4JN3ULCQ44F2G6LZBF2LGNTC/https://seclists.org/bugtraq/2019/Aug/47https://seclists.org/bugtraq/2019/Oct/24https://security.gentoo.org/glsa/201909-04https://security.netapp.com/advisory/ntap-20190905-0003/https://support.f5.com/csp/article/K30442259https://usn.ubuntu.com/4113-1/https://www.debian.org/security/2019/dsa-4509https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-09-26
Published