Information Disclosure Vulnerability in FreedomBox by FreedomBox Team
CVE-2020-25073
5.3MEDIUM
What is CVE-2020-25073?
FreedomBox versions up to 20.13 are affected by a vulnerability that allows remote attackers to access sensitive information via the Apache HTTP Server's /server-status page. The issue arises when connections from the Tor onion service or PageKite are incorrectly recognized as local connections, potentially exposing critical server details. This vulnerability affects both the freedombox and plinth packages across various Linux distributions, contingent upon the Apache mod_status module being enabled, thereby increasing the risk for users who have not properly secured their server configurations.