Odysseus RCE Exploit Found in Apache HTTP Server

A critical Remote Code Execution (RCE) vulnerability in the Apache HTTP Server software has been discovered in the Apache HTTP Server 2.4.41 and later versions. Researchers have identified a way to exploit this vulnerability using a specially crafted HTTP request to gain unauthorized access to a ser

A newly discovered RCE exploit, dubbed Odysseus, takes advantage of a buffer overflow in the Apache HTTP Server's handling of HTTP requests. The vulnerability was discovered by researchers from the non-profit organization CERT/CC. This vulnerability affects Apache HTTP Server versions 2.4.41 and later, with the most recent version being 2.4.50. The exploit relies on sending a malicious HTTP request to the server, which can execute arbitrary code on the server. This could potentially lead to a takeover of the entire server, allowing attackers to access sensitive data or launch further attacks. The vulnerability is rated as critical, and affected servers should be updated to the latest version of Apache HTTP Server immediately.

Source: The Hacker News