{"id":2249,"date":"2021-03-18T22:54:06","date_gmt":"2021-03-19T03:54:06","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2249"},"modified":"2021-03-18T22:54:07","modified_gmt":"2021-03-19T03:54:07","slug":"apache-http-server-and-its-vulnerabilites","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/","title":{"rendered":"Apache HTTP Server and its vulnerabilites"},"content":{"rendered":"\n<p>Apache HTTP Server is free, open source web server software for Unix platforms that runs 46% of the world&#8217;s web sites. It is maintained and developed by the Apache Software Foundation.<\/p>\n\n\n\n<p>It allows website owners to serve content on the web, hence the name &#8220;web server&#8221;. It is one of the oldest and most reliable web servers, with the first version released more than 20 years ago, in 1995, unfortunately, as it is already quite old, it has one or another vulnerability which we must be careful about.<\/p>\n\n\n\n<p>Several vulnerabilities have been discovered in the Apache web server, the most serious of which could allow remote code execution. The Apache web server is software developed by the Apache Software Foundation as a free, open source tool used to host websites. Successful exploitation of the most serious of these vulnerabilities could allow an attacker to execute remote code in the context of the affected application. Depending on the privileges associated with the application, an attacker could view, change, or delete data. If this application has been configured to have fewer user rights on the system, the exploitation of the most serious of these vulnerabilities could have less impact than if it were configured with administrative rights.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerabilities that we can find in the open source Apache<\/h2>\n\n\n\n<p>It is extremely important that you have updated since these vulnerabilities affect Apache Versions 2.4.43 and earlier, not only this but for government entities that have this it is extremely important to update Apache.<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-11984<\/em><\/strong><\/p>\n\n\n\n<p>A possible remote code execution vulnerability due to a buffer overflow with the mod_uwsgi module.<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-11993<\/em><\/strong><\/p>\n\n\n\n<p>A denial of service vulnerability that is triggered when trace \/ debugging is enabled.<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-9490<\/em><\/strong><\/p>\n\n\n\n<p>A denial of service vulnerability is triggered when a PUSH packet is sent using the &#8216;Cache-Digest&#8217; header.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/crlf-injection-a-vulnerability-that-attacks-servers\/\">CRLF Injection \u2013 A Vulnerability that attacks servers<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/php-vulnerabilities-and-risks\/\">PHP Vulnerabilities and risks<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apache HTTP Server is free, open source web server software for Unix platforms that runs 46% of the world&#8217;s web sites. It is maintained and developed by the Apache Software Foundation. It allows website owners to serve content on the web, hence the name &#8220;web server&#8221;. It is one of the oldest and most reliable [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2252,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,197],"class_list":["post-2249","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-vulnerabilities"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apache HTTP Server and its vulnerabilites - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Apache HTTP server, is a open source web server software, its widely used by many companies, we must be careful with the vulnerabilities....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache HTTP Server and its vulnerabilites - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Apache HTTP server, is a open source web server software, its widely used by many companies, we must be careful with the vulnerabilities....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-19T03:54:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-19T03:54:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/03\/vulne.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"666\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Apache HTTP Server and its vulnerabilites\",\"datePublished\":\"2021-03-19T03:54:06+00:00\",\"dateModified\":\"2021-03-19T03:54:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/\"},\"wordCount\":317,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/vulne.jpg\",\"keywords\":[\"Cybersecurity\",\"Vulnerabilities\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/\",\"name\":\"Apache HTTP Server and its vulnerabilites - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/vulne.jpg\",\"datePublished\":\"2021-03-19T03:54:06+00:00\",\"dateModified\":\"2021-03-19T03:54:07+00:00\",\"description\":\"Apache HTTP server, is a open source web server software, its widely used by many companies, we must be careful with the vulnerabilities....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/vulne.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/vulne.jpg\",\"width\":1000,\"height\":666},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/apache-http-server-and-its-vulnerabilites\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apache HTTP Server and its vulnerabilites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apache HTTP Server and its vulnerabilites - Truxgo Server Blog","description":"Apache HTTP server, is a open source web server software, its widely used by many companies, we must be careful with the vulnerabilities....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/","og_locale":"es_MX","og_type":"article","og_title":"Apache HTTP Server and its vulnerabilites - Truxgo Server Blog","og_description":"Apache HTTP server, is a open source web server software, its widely used by many companies, we must be careful with the vulnerabilities....","og_url":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-03-19T03:54:06+00:00","article_modified_time":"2021-03-19T03:54:07+00:00","og_image":[{"width":1000,"height":666,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/03\/vulne.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Apache HTTP Server and its vulnerabilites","datePublished":"2021-03-19T03:54:06+00:00","dateModified":"2021-03-19T03:54:07+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/"},"wordCount":317,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/03\/vulne.jpg","keywords":["Cybersecurity","Vulnerabilities"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/","url":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/","name":"Apache HTTP Server and its vulnerabilites - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/03\/vulne.jpg","datePublished":"2021-03-19T03:54:06+00:00","dateModified":"2021-03-19T03:54:07+00:00","description":"Apache HTTP server, is a open source web server software, its widely used by many companies, we must be careful with the vulnerabilities....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/03\/vulne.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/03\/vulne.jpg","width":1000,"height":666},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/apache-http-server-and-its-vulnerabilites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Apache HTTP Server and its vulnerabilites"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2249"}],"version-history":[{"count":4,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2249\/revisions"}],"predecessor-version":[{"id":2265,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2249\/revisions\/2265"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2252"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}