In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1927
Reference (s):
- https://httpd.apache.org/security/vulnerabilities_24.html
- URL: https://httpd.apache.org/security/vulnerabilities_24.html
- https://security.netapp.com/advisory/ntap-20200413-0002/
- URL: https://security.netapp.com/advisory/ntap-20200413-0002/
- DEBIAN:DSA-4757