Executive brief
Apache HTTP Server's mod_rewrite contains an improper escaping vulnerability when substitutions in server context use backreferences or variables as the first segment. This allows an attacker to map URLs to unauthorized filesystem locations, potentially leading to remote code execution or source code disclosure.
Affected products
- Apache HTTP Server 2.4.0 to 2.4.59 (up to and including 2.4.59)
- SonicWall SMA 200 Firmware up to (excluding) 10.2.1.14-75sv
- SonicWall SMA 210 Firmware up to (excluding) 10.2.1.14-75sv
- SonicWall SMA 400 Firmware up to (excluding) 10.2.1.14-75sv
- SonicWall SMA 410 Firmware up to (excluding) 10.2.1.14-75sv
- SonicWall SMA 500v Firmware up to (excluding) 10.2.1.14-75sv
- NetApp ONTAP 9
Timeline
- 2024-07-01: disclosed: Public disclosure via oss-security mailing list
- 2025-05-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-05-01: advisory: NVD publication date
- 2025-05-22: other: CISA KEV remediation due date