CVE-2024-40725

Description

A flaw was found in httpd. The fix for CVE-2024-39884 ignores some uses of the legacy content-type based configuration of handlers. "AddType" and similar configurations, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.

Statement

The httpd package as shipped in Red Hat Enterprise Linux 6, 7, 8, 9 and in Red Hat JBoss Core Services is not affected by this vulnerability because the vulnerable code was introduced in a newer version of httpd.

This flaw allows unauthenticated remote users to view local content that was not intended to be served or shared, such as PHP scripts. As the disclosed information presents a serious impact to confidentiality, this flaw has been rated with an important severity.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.55.35.3
Attack VectorNetworkNetworkNetwork
Attack ComplexityLowLowLow
Privileges RequiredNoneNoneNone
User InteractionNoneNoneNone
ScopeUnchangedUnchangedUnchanged
ConfidentialityHighLowLow
Integrity ImpactNoneNoneNone
Availability ImpactNoneNoneNone

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Red Hat CVSS v3 Score Explanation

See the 'Statement' section for an explanation of the difference between the CVSS from Red Hat and NVD.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

An adversary that gains access to a resource exposed to a wrong sphere could potentially retrieve private data from that resource, thus breaking the intended confidentiality of that data.

Integrity

Technical Impact: Modify Application Data

An adversary that gains access to a resource exposed to a wrong sphere could potentially modify data held within that resource, thus breaking the intended integrity of that data and causing the system relying on that resource to make unintended decisions.

Other

Technical Impact: Varies by Context

The consequences may vary widely depending on how the product uses the affected resource.

Frequently Asked Questions

Want to get errata notifications? Sign up here.