mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Jun 18, 2010 |
| Apache Httpd 2_2_x Timeout Detection Flaw Mod_proxy_http | — | — | Aug 16, 2010 | Jun 18, 2010 |
| Apple Osx Airport | — | Apply OS X security update 2011-001Upgrade macOS to the latest versionApply OS X security update 2011-004 | Aug 28, 2015 | Jun 18, 2010 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-001 | Dec 16, 2011 | Jun 18, 2010 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Jun 18, 2010 |
| Suse | — | Upgrade apache2-develUpgrade apache2-manualUpgrade apache2-example-pagesUpgrade apache2-preforkUpgrade apache2-eventUpgrade apache2-workerUpgrade apache2-docUpgrade apache2Upgrade apache2-utils | Aug 9, 2024 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub