The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 20, 2014 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 20, 2014 | Jul 20, 2014 |
| Apple Osx Adminframework | — | Upgrade macOS to the latest versionApply OS X security update 2015-004 | Aug 28, 2015 | Jul 20, 2014 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2015-004 | Mar 29, 2016 | Jul 20, 2014 |
| Centos_linux | — | Upgrade httpd-develUpgrade httpd-toolsUpgrade mod_proxy_htmlUpgrade mod_sslUpgrade httpd-manualUpgrade mod_sessionUpgrade httpdUpgrade mod_ldap | Dec 1, 2016 | Jul 20, 2014 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jul 20, 2014 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jul 19, 2014 |
| Oracle Solaris | — | Upgrade web/server/apache-22 to version 2.2.27-0.175.2.2.0.3.0 on Solaris 11.2 | May 29, 2017 | Jul 20, 2014 |
| Oracle_linux | — | Upgrade mod_sslUpgrade httpd-toolsUpgrade httpd-develUpgrade httpdUpgrade mod_proxy_htmlUpgrade httpd-manualUpgrade mod_sessionUpgrade mod_ldap | Oct 16, 2024 | Jul 20, 2014 |
| Suse | — | Upgrade apache2-example-pagesUpgrade apache2-docUpgrade apache2-workerUpgrade apache2-utilsUpgrade apache2-preforkUpgrade apache2-develUpgrade apache2 | Dec 18, 2015 | Jul 20, 2014 |
| Ubuntu | — | Upgrade apache2.2-binUpgrade apache2-bin | Nov 8, 2024 | Jul 20, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub