Apache2: A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing…
A cross-site scripting (XSS) vulnerability exists in the mod_proxy_ftp module of Apache HTTP Server versions 2.4.67 and earlier. This vulnerability occurs during the generation of HTML directory listings when listing FTP directory contents via forward or reverse proxy configurations. The issue is fixed in Apache HTTP Server version 2.4.68. Users running affected versions are advised to upgrade to this fixed version to mitigate the vulnerability.
AI Analysis
Technical Summary
The Apache HTTP Server mod_proxy_ftp module in versions 2.4.67 and earlier improperly sanitizes HTML directory listings generated when listing FTP directory contents through forward or reverse proxy configurations. This flaw allows a cross-site scripting vulnerability, enabling an attacker to inject malicious scripts into the directory listing output. The vulnerability is resolved in version 2.4.68, which includes the necessary fixes to prevent script injection.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the user's browser when viewing FTP directory listings served by the vulnerable Apache HTTP Server. This could lead to information disclosure or other client-side impacts related to cross-site scripting. The vulnerability does not affect server availability or integrity directly.
Mitigation Recommendations
An official fix is available in Apache HTTP Server version 2.4.68. Users are strongly recommended to upgrade to this version or later to remediate the vulnerability. No additional mitigation steps are indicated beyond applying the official update.
Apache2: A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing…
Description
A cross-site scripting (XSS) vulnerability exists in the mod_proxy_ftp module of Apache HTTP Server versions 2.4.67 and earlier. This vulnerability occurs during the generation of HTML directory listings when listing FTP directory contents via forward or reverse proxy configurations. The issue is fixed in Apache HTTP Server version 2.4.68. Users running affected versions are advised to upgrade to this fixed version to mitigate the vulnerability.
CVSS v3.1
Score 6.1medium
Affected software
pkg:deb/ubuntu/[email protected]+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm20?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm11?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/[email protected]+esm6?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Apache HTTP Server mod_proxy_ftp module in versions 2.4.67 and earlier improperly sanitizes HTML directory listings generated when listing FTP directory contents through forward or reverse proxy configurations. This flaw allows a cross-site scripting vulnerability, enabling an attacker to inject malicious scripts into the directory listing output. The vulnerability is resolved in version 2.4.68, which includes the necessary fixes to prevent script injection.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the user's browser when viewing FTP directory listings served by the vulnerable Apache HTTP Server. This could lead to information disclosure or other client-side impacts related to cross-site scripting. The vulnerability does not affect server availability or integrity directly.
Mitigation Recommendations
An official fix is available in Apache HTTP Server version 2.4.68. Users are strongly recommended to upgrade to this version or later to remediate the vulnerability. No additional mitigation steps are indicated beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-29170
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a61511f9c2644c7f8da5f63
Added to database: 07/22/2026, 23:24:15 UTC
Last enriched: 07/23/2026, 00:23:43 UTC
Last updated: 07/31/2026, 19:24:50 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.