在 Apache Software Foundation 的 Apache HTTP Server 2.4.69 之前版本中,mod_dav_fs 模块的内部状态文件可被外部方访问。该漏洞存在于所有平台,允许远程客户端通过向 .DAV 状态目录发送 GET 请求,读取其无权创建(author)的资源所关联的 WebDAV 死属性(dead properties)。 此问题影响 Apache HTTP Server 2.4.0 至 2.4.68 版本。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | 2.4.0 ~ 2.4.68 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-88789 | 8.6 HIGH | Apache Camel Quarkus 强制Xalan工厂致加固失效 |
| CVE-2026-94250 | 8.2 HIGH | Apache APISIX 批量响应聚合内存耗尽漏洞 |
| CVE-2026-94212 | 6.4 MEDIUM | Apache APISIX SAML认证未授权冒充漏洞 |
| CVE-2026-94269 | 6.3 MEDIUM | Apache APISIX 路由授权不匹配漏洞 |
| CVE-2026-78242 | 5.7 MEDIUM | Apache APISIX 日志脱敏失败漏洞 |
| CVE-2026-82806 | 5.3 MEDIUM | Apache APISIX 静态权限列表跨请求污染漏洞 |
| CVE-2026-94276 | 5.1 MEDIUM | Apache APISIX OIDC验证绕过漏洞 |
| CVE-2026-94220 | 2.1 LOW | Apache APISIX 飞书钉钉插件会话固定漏洞 |
| CVE-2026-56153 | Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char | |
| CVE-2026-42528 | Apache HTTP Server: mod_dav shared lock overflow | |
| CVE-2026-42356 | Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI direct | |
| CVE-2026-46729 | Apache HTTP Server: mod_heartmonitor denial of service | |
| CVE-2026-47360 | Apache HTTP Server: mod_session: Session cookie not removed during internal redirect | |
| CVE-2026-48005 | Apache HTTP Server: mod_auth_digest reauthentication attack | |
| CVE-2026-63686 | Apache HTTP Server: mod_xml2enc crash on charset conversion failure | |
| CVE-2026-56154 | Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...} | |
| CVE-2026-56449 | Apache HTTP Server: mod_proxy_html: crash in dump_content | |
| CVE-2026-57941 | Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-ent | |
| CVE-2026-59685 | Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on C | |
| CVE-2026-59797 | Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function |
显示前 20 条,共 28 条。 查看全部 → →
暂无评论