Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
The mod_rewrite module incorrectly processes special characters during substitution in the server context, when the first segment of the substitution is a backreference or variable. This allows an attacker to construct a specially crafted URL that is mapped to a file system location accessible to the server but normally unreachable through any public URL. The consequence can be both source code disclosure and code execution on the server. The vendor introduced a new RewriteRule flag called 'UnsafePrefixStat', allowing administrators to restore the previous behavior after ensuring the security of the applied rules.
An attacker can gain unauthorized access to server system files (source code disclosure) or cause remote code execution (RCE) without the need for authentication.
Update Apache HTTP Server to a version higher than 2.4.59 as soon as possible, applying patches indicated by the vendor at https://httpd.apache.org/security/vulnerabilities_24.html. Administrators using unsafe RewriteRule rules should verify their correctness before any potential use of the 'UnsafePrefixStat' flag. For NetApp and SonicWall products, apply patches available from the vendor according to the references.
Apache HTTP Server versions 2.4.59 and earlier; dependent products: NetApp ONTAP 9, SonicWall SMA 200 Firmware, SonicWall SMA 200, SonicWall SMA 210 Firmware
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache HTTP Server
APPApache2.4.0 – 2.4.60 (excl.)Netapp Ontap 9
APPNetappall versionsSonicwall Sma 200
HWSonicwallall versionsSonicwall Sma 200 Firmware
OSSonicwall< 10.2.1.14-75svSonicwall Sma 210
HWSonicwallall versionsSonicwall Sma 210 Firmware
OSSonicwall< 10.2.1.14-75svSonicwall Sma 400
HWSonicwallall versionsSonicwall Sma 400 Firmware
OSSonicwall< 10.2.1.14-75svSonicwall Sma 410
HWSonicwallall versionsSonicwall Sma 410 Firmware
OSSonicwall< 10.2.1.14-75svSonicwall Sma 500v
HWSonicwallall versionsSonicwall Sma 500v Firmware
OSSonicwall< 10.2.1.14-75sv
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- HTTP Server
- Added to KEVi
- May 1, 2025
- Remediation deadline (US Federal)i
- May 22, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
Related vulnerabilities
Stack-based buffer overflow w SonicWall SMA 100 — zdalny RCE bez uwierzytelnienia
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)
Apache HTTP Server 2.4.49 — path traversal i RCE (aktywnie exploitowany)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
SQL Injection w urządzeniach SonicWall SRA/SMA — zdalne przejęcie kontroli