A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mod_proxy_clusterUpgrade mod_jk | May 8, 2024 | Dec 12, 2023 |
| Oracle_linux | — | Upgrade mod_jkUpgrade mod_proxy_cluster | May 7, 2024 | Dec 12, 2023 |
| Redhat_linux | — | Upgrade mod_proxy_cluster-debugsourceUpgrade mod_jk-debugsourceUpgrade mod_jk-debuginfoUpgrade mod_jkUpgrade mod_proxy_cluster-debuginfoUpgrade mod_proxy_cluster | May 1, 2024 | Dec 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub