lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Oct 3, 2008 |
| Freebsd | — | Upgrade lighttpd | Dec 10, 2025 | Sep 27, 2008 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd. | Oct 30, 2017 | Oct 3, 2008 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Dec 8, 2014 | Oct 3, 2008 |
| Suse | — | Upgrade lighttpd-mod_mysql_vhostUpgrade lighttpd-mod_cmlUpgrade suse-releaseUpgrade lighttpd-mod_webdavUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_rrdtoolUpgrade lighttpdUpgrade lighttpd-mod_magnet | Feb 17, 2015 | Oct 3, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub