mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lighttpd | Jul 30, 2024 | Jun 9, 2015 |
| Freebsd | — | Upgrade lighttpd | Dec 10, 2025 | Aug 10, 2015 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Nov 25, 2016 | Jun 9, 2015 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3 | May 29, 2017 | Jun 9, 2015 |
| Suse | — | Upgrade lighttpd-mod_webdavUpgrade lighttpd-mod_cmlUpgrade lighttpd-mod_mysql_vhostUpgrade lighttpdUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpd-mod_rrdtool | Mar 18, 2017 | Jun 9, 2015 |
| Ubuntu | — | Upgrade lighttpd (Ubuntu Pro) | Mar 22, 2023 | Jun 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub