RHSA-2020:2263MediumCVSS 6.1
Red Hat Security Advisory: httpd24-httpd and httpd24-mod_md security and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-10098 — httpd: mod_rewrite potential open redirect CVE-2020-1927 — httpd: mod_rewrite configurations vulnerable to open redirect
🎯 Affected products148
- Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6)
- Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6)
- Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- httpd24-httpd-0:2.4.34-18.el6.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6)
- httpd24-httpd-0:2.4.34-18.el6.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6)
- httpd24-httpd-0:2.4.34-18.el6.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6)
- httpd24-httpd-0:2.4.34-18.el6.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6)
- httpd24-httpd-0:2.4.34-18.el7.aarch64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- httpd24-httpd-0:2.4.34-18.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- httpd24-httpd-0:2.4.34-18.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- httpd24-httpd-0:2.4.34-18.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- httpd24-httpd-0:2.4.34-18.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- httpd24-httpd-0:2.4.34-18.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- httpd24-httpd-0:2.4.34-18.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- httpd24-httpd-0:2.4.34-18.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- httpd24-httpd-0:2.4.34-18.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- httpd24-httpd-0:2.4.34-18.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- httpd24-httpd-0:2.4.34-18.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- httpd24-httpd-0:2.4.34-18.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- httpd24-httpd-0:2.4.34-18.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- httpd24-httpd-0:2.4.34-18.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7)
- httpd24-httpd-0:2.4.34-18.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- httpd24-httpd-debuginfo-0:2.4.34-18.el6.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6)
- httpd24-httpd-debuginfo-0:2.4.34-18.el6.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6)
- httpd24-httpd-debuginfo-0:2.4.34-18.el7.aarch64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- httpd24-httpd-debuginfo-0:2.4.34-18.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- httpd24-httpd-debuginfo-0:2.4.34-18.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6)
- +118 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: This flaw requires the use of certain Rewrite configuration directives. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Rewrite' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2020:2263
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_software_collections/3/html/3.5_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820761
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2263.json