Lucene search

K
httpdApache Team FoundationHTTPD:F40F126B7C20496F4F246EC66E3FF287
HistoryAug 16, 2012 - 12:00 a.m.

Apache Httpd < 2.4.3 : Response mixup when using mod_proxy_ajp or mod_proxy_http

2012-08-1600:00:00
Apache Team Foundation
httpd.apache.org
20

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

66.1%

The modules mod_proxy_ajp and mod_proxy_http did not always close the connection to the back end server when necessary as part of error handling. This could lead to an information disclosure due to a response mixup between users.

Affected configurations

Vulners
Node
apacheapache_httpdMatch2.4.2
OR
apacheapache_httpdMatch2.4.1
VendorProductVersionCPE
apacheapache_httpd2.4.2cpe:2.3:a:apache:apache_httpd:2.4.2:*:*:*:*:*:*:*
apacheapache_httpd2.4.1cpe:2.3:a:apache:apache_httpd:2.4.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

66.1%