
Cloud Vulnerability DB
A community-led vulnerabilities database
FreedomBox through version 20.13 contained a security vulnerability that allowed remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server. The issue occurred because connections from the Tor onion service or PageKite were incorrectly treated as local connections, affecting both the freedombox and plinth packages of some Linux distributions when the Apache mod_status module was enabled (NVD).
The vulnerability was assigned a CVSS v3.1 base score of 5.3 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The issue stemmed from improper access control where the Apache server's status page, typically restricted to localhost access only, was accessible through Tor onion service and PageKite connections as these were incorrectly identified as local connections (NVD, Debian Issue).
The vulnerability exposed sensitive server information through the /server-status page of the Apache HTTP Server to remote attackers when accessed via Tor onion service or PageKite connections. This information disclosure could potentially be used by attackers for reconnaissance and to gather details about the server configuration (NVD).
The vulnerability was relatively easy to exploit as it required no special privileges or user interaction. An attacker only needed to access the /server-status page through a Tor onion service or PageKite connection to view sensitive server information (Debian Issue).
The issue was addressed in the Debian 10.7 update by disabling the mod_status module in the plinth package. Users running PageKite or Tor Onion Service could manually mitigate the vulnerability by disabling mod_status using the command: sudo a2dismod status && sudo systemctl restart apache2 (Debian Announcement, Debian Issue).
The vulnerability was initially reported through IRC channels and subsequently addressed in the Debian community. The FreedomBox team planned to make announcements on their forum, mailing list, and social media to inform users about the vulnerability and provide mitigation instructions (Debian Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."