Fedora Account System
Red Hat Associate
Red Hat Customer
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:41906 https://access.redhat.com/errata/RHSA-2026:41906
This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62.SP5 Via RHSA-2026:56869 https://access.redhat.com/errata/RHSA-2026:56869
This issue has been addressed in the following products: JBoss Core Services for RHEL 8 Via RHSA-2026:56868 https://access.redhat.com/errata/RHSA-2026:56868