mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Mar 10, 2008 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd. | Oct 30, 2017 | Mar 10, 2008 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Mar 10, 2008 |
| Suse | — | Upgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_cmlUpgrade lighttpd-mod_webdavUpgrade lighttpdUpgrade lighttpd-mod_mysql_vhost | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade lighttpd | Nov 19, 2024 | Mar 10, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub