An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade lighttpd | Aug 13, 2019 | Nov 7, 2018 |
| Debian | — | Upgrade lighttpd | Jan 20, 2022 | Nov 7, 2018 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Feb 25, 2019 | Nov 7, 2018 |
| Oracle Solaris | — | Upgrade web/server/lighttpd-14 to version 1.4.54-11.4.15.0.1.2.0 on Solaris 11.4 | Nov 20, 2019 | Nov 7, 2018 |
| Suse | — | Upgrade lighttpd-mod_vhostdb_pgsqlUpgrade lighttpd-mod_authn_mysqlUpgrade lighttpd-mod_authn_ldapUpgrade lighttpd-mod_webdavUpgrade lighttpd-mod_vhostdb_dbiUpgrade lighttpd-mod_authn_pamUpgrade lighttpd-mod_trigger_b4_dlUpgrade lighttpdUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_mysql_vhostUpgrade lighttpd-mod_vhostdb_ldapUpgrade lighttpd-mod_cmlUpgrade lighttpd-mod_geoipUpgrade lighttpd-mod_authn_gssapiUpgrade lighttpd-mod_vhostdb_mysqlUpgrade lighttpd-mod_authn_saslUpgrade lighttpd-mod_maxminddb | Oct 22, 2019 | Nov 7, 2018 |
| Ubuntu | — | Upgrade lighttpd (Ubuntu Pro) | Mar 22, 2023 | Nov 7, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub