BIT-apache-2025-66200

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/apache/BIT-apache-2025-66200.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-apache-2025-66200
Aliases
Published
2025-12-09T11:38:20.150Z
Modified
2025-12-09T12:27:54.957368Z
Summary
Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo
Details

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.

This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.

Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / apache

Package

Name
apache
Purl
pkg:bitnami/apache

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.4.7
Fixed
2.4.66