Lucene search

K
httpdApache Team FoundationHTTPD:9A9EDD16AFCBADF47F5131790CE881C5
HistoryJan 15, 2012 - 12:00 a.m.

Apache Httpd < 2.0.65 : error responses can expose cookies

2012-01-1500:00:00
Apache Team Foundation
httpd.apache.org
10

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.717 High

EPSS

Percentile

98.1%

A flaw was found in the default error response for status code 400. This flaw could be used by an attacker to expose “httpOnly” cookies when no custom ErrorDocument is specified.

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.717 High

EPSS

Percentile

98.1%