Apache web server bug grants root access on shared hosting environments

Apache web server bug grants root access on shared hosting environments

Logo: Apache Software Foundation // Composition: ZDNet

This week, the Apache Software Foundation has patched a severe vulnerability in the Apache (httpd) web server project that could –under certain circumstances– allow rogue server scripts to execute code with root privileges and take over the underlying server. Because on most Unix systems Apache httpd runs under the root user, any threat actor who has planted a malicious CGI script on an Apache server can use CVE-2019-0211 to take over the underlying system running the Apache httpd process, and inherently control the entire machine. Non-shared Apache servers also in danger
But Fol also told ZDNet that CVE-2019-0211, just by its presence, automatically augments any other server security issue –even for Apache web servers not part of shared-hosting environments.

Source: www.zdnet.com