CVE-2017-15715: Apache HTTP Server

High severity, CVSS 8.1. EPSS: 85.5% chance of exploitation in the next 30 days.

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

Affected products

  • Apache HTTP Server: from 2.4.0, up to and including 2.4.29
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp Santricity Cloud Connector: affected versions not specified
  • Netapp Storage Automation Store: affected versions not specified
  • Netapp Storagegrid: affected versions not specified
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 7.4 only; version 7.5 only; version 7.6 only

Published 2018-03-26. Last modified 2026-06-17.