mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Aug 5, 2010 |
| Apache Httpd 2_2_x Timeout Detection Flaw Mod_proxy_http | — | — | Aug 16, 2010 | Aug 5, 2010 |
| Centos_linux | — | Upgrade httpd-manualUpgrade httpdUpgrade httpd-develUpgrade mod_ssl | Dec 1, 2016 | Aug 5, 2010 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Aug 5, 2010 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Dec 29, 2015 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Aug 5, 2010 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Aug 5, 2010 |
| Oracle_linux | — | Upgrade httpdUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-devel | Oct 16, 2024 | Aug 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub