CVE-2020-25073
Linux Debian vulnerability analysis and mitigation

Overview

FreedomBox through version 20.13 contained a security vulnerability that allowed remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server. The issue occurred because connections from the Tor onion service or PageKite were incorrectly treated as local connections, affecting both the freedombox and plinth packages of some Linux distributions when the Apache mod_status module was enabled (NVD).

Technical details

The vulnerability was assigned a CVSS v3.1 base score of 5.3 (Medium) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The issue stemmed from improper access control where the Apache server's status page, typically restricted to localhost access only, was accessible through Tor onion service and PageKite connections as these were incorrectly identified as local connections (NVD, Debian Issue).

Impact

The vulnerability exposed sensitive server information through the /server-status page of the Apache HTTP Server to remote attackers when accessed via Tor onion service or PageKite connections. This information disclosure could potentially be used by attackers for reconnaissance and to gather details about the server configuration (NVD).

Exploitability

The vulnerability was relatively easy to exploit as it required no special privileges or user interaction. An attacker only needed to access the /server-status page through a Tor onion service or PageKite connection to view sensitive server information (Debian Issue).

Mitigation and workarounds

The issue was addressed in the Debian 10.7 update by disabling the mod_status module in the plinth package. Users running PageKite or Tor Onion Service could manually mitigate the vulnerability by disabling mod_status using the command: sudo a2dismod status && sudo systemctl restart apache2 (Debian Announcement, Debian Issue).

Community reactions

The vulnerability was initially reported through IRC channels and subsequently addressed in the Debian community. The FreedomBox team planned to make announcements on their forum, mailing list, and social media to inform users about the vulnerability and provide mitigation instructions (Debian Issue).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78683CRITICAL9.4
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78682HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78681HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78680HIGH8.5
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78679HIGH7.1
  • Linux Debian logoLinux Debian
  • python-git
NoNoAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management