CVE-2019-10098

CVE-2019-10098

Vendor N/A
Product Apache HTTP Server
Weakness CWE-601 · Open redirect
Published September 25, 2019
Last update August 4, 2024

CVSS base score

What the vulnerability does

01Description

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

Key dates

02Disclosure timeline

September 25, 2019 CVE published
August 4, 2024 Record updated