Best Solutions
Best Solutions
Best Solutions
Order deny,allow
Deny from all
Allow from 127.0.0.1
</Location>
Once these changes have been made, the Apache server needs to be restarted.
Resolves 1 vulnerability
Remove/disable SMB1
Configuration remediation steps
For Windows 8.1 and Windows Server 2012 R2, removing SMB1 is trivial. On older OS'es it can't be removed but should be disabled.
This article contains system-specific details: How to detect, enable and disable SMBv1, SMBv2, and SMBv3 in Windows and Windows
Server
Resolves 1 vulnerability
Apache HTTPD: bypass with a trailing newline in the file name (CVE-2017-15715)
Apache HTTPD: Apache httpd URL normalization inconsistincy (CVE-2019-0220)
Apache HTTPD: Denial of service in mod_lua r:parsebody (CVE-2022-29404)
Apache HTTPD: DoS for HTTP/2 connections by continuous SETTINGS (CVE-2018-11763)
Apache HTTPD: DoS for HTTP/2 connections by crafted requests (CVE-2018-1333)
Apache HTTPD: DoS for HTTP/2 connections via slow request bodies (CVE-2018-17189)
Apache HTTPD: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier (CVE-2022-22720)
Apache HTTPD: Improper Handling of Insufficient Privileges (CVE-2020-13938)
Apache HTTPD: Information Disclosure in mod_lua with websockets (CVE-2022-30556)
Apache HTTPD: Limited cross-site scripting in mod_proxy error page (CVE-2019-10092)
Apache HTTPD: NULL pointer dereference in httpd core (CVE-2021-34798)
Apache HTTPD: Out of bound write in mod_authnz_ldap when using too small Accept-Language values (CVE-2017-15710)
Apache HTTPD: Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and
earlier (CVE-2021-44224)
Apache HTTPD: Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and
earlier (CVE-2021-44790)
Apache HTTPD: Possible out of bound access after failure in reading the HTTP request (CVE-2018-1301)
Apache HTTPD: Possible out of bound read in mod_cache_socache (CVE-2018-1303)
Apache HTTPD: Possible write of after free on HTTP/2 stream shutdown (CVE-2018-1302)
Apache HTTPD: Push Diary Crash on Specifically Crafted HTTP/2 Header (CVE-2020-11993)
Apache HTTPD: Push Diary Crash on Specifically Crafted HTTP/2 Header (CVE-2020-9490)
Apache HTTPD: Read beyond bounds in ap_strcmp_match() (CVE-2022-28615)
Apache HTTPD: Request splitting via HTTP/2 method injection and mod_proxy (CVE-2021-33193)
Apache HTTPD: Tampering of mod_session data for CGI applications (CVE-2018-1283)
Apache HTTPD: Weak Digest auth nonce generation in mod_auth_digest (CVE-2018-1312)
Apache HTTPD: ap_escape_quotes buffer overflow (CVE-2021-39275)
Apache HTTPD: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody (CVE-2022-22721)
and 20 additional vulnerabilities ...