mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 29, 2013 | Jul 23, 2013 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jul 23, 2013 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jul 20, 2013 |
| Suse | — | Upgrade apache2-workerUpgrade apache2-preforkUpgrade apache2-utilsUpgrade apache2-example-pagesUpgrade apache2Upgrade apache2-docUpgrade apache2-devel | Aug 9, 2024 | Jul 23, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub