jbcs-httpd24-mod_security vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the jbcs-httpd24-mod_security package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Incorrect Default Permissions

<0:2.9.3-42.el7jbcs
  • M
Improper Input Validation

<0:2.9.3-42.el7jbcs
  • H
Use After Free

<0:2.9.2-63.GA.jbcs.el7
  • M
Detection of Error Condition Without Action

<0:2.9.3-36.el7jbcs
  • M
Resource Exhaustion

<0:2.9.3-36.el7jbcs
  • M
Improper Validation of Certificate with Host Mismatch

<0:2.9.3-36.el7jbcs
  • M
Missing Release of Resource after Effective Lifetime

<0:2.9.3-36.el7jbcs
  • M
Improper Certificate Validation

<0:2.9.3-36.el7jbcs
  • M
Misinterpretation of Input

<0:2.9.3-36.el7jbcs
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:2.9.3-40.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:2.9.3-40.el7jbcs
  • H
Server-Side Request Forgery (SSRF)

<0:2.9.2-65.GA.jbcs.el7
  • M
Out-of-Bounds

<0:2.9.2-67.GA.jbcs.el7
  • M
Out-of-bounds Read

<0:2.9.2-67.GA.jbcs.el7
  • M
Incorrect Calculation of Buffer Size

<0:2.9.2-57.GA.jbcs.el7
  • H
Allocation of Resources Without Limits or Throttling

<0:2.9.2-51.GA.jbcs.el7
  • L
Use After Free

<0:2.9.2-20.GA.jbcs.el7
  • H
Use After Free

<0:2.9.2-68.GA.jbcs.el7
  • H
HTTP Request Smuggling

<0:2.9.2-68.GA.jbcs.el7
  • H
Out-of-bounds Write

<0:2.9.2-68.GA.jbcs.el7
  • H
Improper Input Validation

<0:2.9.3-40.el7jbcs
  • H
NULL Pointer Dereference

<0:2.9.3-40.el7jbcs
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:2.9.3-40.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:2.9.3-40.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:2.9.3-40.el7jbcs
  • H
Improper Encoding or Escaping of Output

<0:2.9.3-40.el7jbcs
  • M
Detection of Error Condition Without Action

<0:2.9.3-36.el7jbcs
  • M
Resource Exhaustion

<0:2.9.3-36.el7jbcs
  • M
Improper Validation of Certificate with Host Mismatch

<0:2.9.3-36.el7jbcs
  • M
Missing Release of Resource after Effective Lifetime

<0:2.9.3-36.el7jbcs
  • M
Improper Certificate Validation

<0:2.9.3-36.el7jbcs
  • M
Misinterpretation of Input

<0:2.9.3-36.el7jbcs
  • M
Expected Behavior Violation

<0:2.9.3-29.el7jbcs
  • M
Use After Free

<0:2.9.3-29.el7jbcs
  • M
Improper Certificate Validation

<0:2.9.3-29.el7jbcs
  • H
Out-of-Bounds

<0:2.9.1-18.GA.jbcs.el7
  • H
Improper Input Validation

<0:2.9.1-18.GA.jbcs.el7
  • H
Buffer Overflow

<0:2.9.1-18.GA.jbcs.el7
  • M
Improper Certificate Validation

<0:2.9.2-57.GA.jbcs.el7
  • M
HTTP Response Splitting

<0:2.9.3-29.el7jbcs
  • M
Integer Overflow or Wraparound

<0:2.9.3-29.el7jbcs
  • M
Resource Leak

<0:2.9.3-29.el7jbcs
  • M
CVE-2022-48279

<0:2.9.3-29.el7jbcs
  • M
HTTP Response Splitting

<0:2.9.3-29.el7jbcs
  • M
HTTP Request Smuggling

<0:2.9.3-29.el7jbcs
  • H
HTTP Request Smuggling

<0:2.9.2-68.GA.jbcs.el7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:2.9.2-68.GA.jbcs.el7
  • H
Use After Free

<0:2.9.2-68.GA.jbcs.el7
  • H
Authentication Bypass

<0:2.9.2-63.GA.jbcs.el7
  • H
Use After Free

<0:2.9.2-63.GA.jbcs.el7
  • H
Information Exposure

<0:2.9.2-63.GA.jbcs.el7
  • M
NULL Pointer Dereference

<0:2.9.2-67.GA.jbcs.el7
  • M
Incorrect Calculation of Buffer Size

<0:2.9.2-57.GA.jbcs.el7
  • H
Improper Input Validation

<0:2.9.1-19.GA.jbcs.el7
  • M
Incorrect Calculation

<0:2.9.1-23.GA.jbcs.el7
  • M
Information Exposure

<0:2.9.2-67.GA.jbcs.el7
  • H
Server-Side Request Forgery (SSRF)

<0:2.9.2-65.GA.jbcs.el7
  • M
NULL Pointer Dereference

<0:2.9.2-67.GA.jbcs.el7
  • M
Out-of-bounds Read

<0:2.9.2-67.GA.jbcs.el7
  • M
Information Exposure

<0:2.9.1-23.GA.jbcs.el7
  • M
Unchecked Error Condition

<0:2.9.1-23.GA.jbcs.el7
  • M
Incorrect Calculation

<0:2.9.1-23.GA.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:2.9.1-23.GA.jbcs.el7
  • M
Resource Exhaustion

<0:2.9.2-57.GA.jbcs.el7
  • M
Out-of-Bounds

<0:2.9.2-57.GA.jbcs.el7
  • H
Insufficient Session Expiration

<0:2.9.2-16.GA.jbcs.el7
  • H
Improper Certificate Validation

<0:2.9.2-63.GA.jbcs.el7
  • H
Improper Certificate Validation

<0:2.9.2-60.GA.jbcs.el7
  • H
NULL Pointer Dereference

<0:2.9.2-60.GA.jbcs.el7
  • H
Improper Input Validation

<0:2.9.1-19.GA.jbcs.el7
  • H
Improper Input Validation

<0:2.9.1-19.GA.jbcs.el7
  • H
Improper Authentication

<0:2.9.1-19.GA.jbcs.el7
  • H
HTTP Request Smuggling

<0:2.9.2-51.GA.jbcs.el7
  • H
Use After Free

<0:2.9.2-51.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.2-16.GA.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:2.9.1-23.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.1-19.GA.jbcs.el7
  • H
Integer Overflow or Wraparound

<0:2.9.1-18.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.1-19.GA.jbcs.el7
  • M
Out-of-bounds Read

<0:2.9.1-23.GA.jbcs.el7
  • H
Memory Leak

<0:2.9.2-51.GA.jbcs.el7
  • H
Covert Timing Channel

<0:2.9.1-18.GA.jbcs.el7
  • M
Unchecked Error Condition

<0:2.9.1-23.GA.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:2.9.1-23.GA.jbcs.el7
  • H
Out-of-bounds Write

<0:2.9.1-18.GA.jbcs.el7
  • H
Allocation of Resources Without Limits or Throttling

<0:2.9.2-51.GA.jbcs.el7
  • L
Use After Free

<0:2.9.2-20.GA.jbcs.el7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:2.9.2-51.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.2-68.GA.jbcs.el7
  • L
NULL Pointer Dereference

<0:2.9.2-58.GA.jbcs.el7
  • H
NULL Pointer Dereference

<0:2.9.2-68.GA.jbcs.el7
  • H
Out-of-bounds Write

<0:2.9.2-68.GA.jbcs.el7
  • H
Use After Free

<0:2.9.2-68.GA.jbcs.el7
  • H
Use After Free

<0:2.9.2-68.GA.jbcs.el7
  • H
Missing Initialization of a Variable

<0:2.9.2-51.GA.jbcs.el7
  • H
Uncontrolled Recursion

<0:2.9.2-63.GA.jbcs.el7
  • H
Information Exposure

<0:2.9.2-63.GA.jbcs.el7
  • L
Heap-based Buffer Overflow

<0:2.9.2-20.GA.jbcs.el7
  • H
Missing Release of Resource after Effective Lifetime

<0:2.9.2-51.GA.jbcs.el7
  • H
Improper Access Control

<0:2.9.2-16.GA.jbcs.el7
  • L
Path Equivalence

<0:2.9.2-20.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.2-51.GA.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:2.9.2-57.GA.jbcs.el7
  • H
Heap-based Buffer Overflow

<0:2.9.2-51.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.2-16.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.2-16.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.2-16.GA.jbcs.el7
  • H
Resource Exhaustion

<0:2.9.2-16.GA.jbcs.el7
  • H
Covert Timing Channel

<0:2.9.2-16.GA.jbcs.el7
  • H
Covert Timing Channel

<0:2.9.2-16.GA.jbcs.el7
  • M
Improper Input Validation

<0:2.9.2-67.GA.jbcs.el7
  • H
Covert Timing Channel

<0:2.9.1-19.GA.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:2.9.2-67.GA.jbcs.el7
  • M
Out-of-Bounds

<0:2.9.2-67.GA.jbcs.el7
  • M
NULL Pointer Dereference

<0:2.9.2-67.GA.jbcs.el7
  • M
NULL Pointer Dereference

<0:2.9.2-67.GA.jbcs.el7
  • H
Information Exposure

<0:2.9.2-63.GA.jbcs.el7
  • M
HTTP Response Splitting

<0:2.9.1-23.GA.jbcs.el7
  • M
Out-of-Bounds

<0:2.9.2-67.GA.jbcs.el7
  • M
Integer Overflow or Wraparound

<0:2.9.2-67.GA.jbcs.el7
  • M
Out-of-bounds Read

<0:2.9.2-67.GA.jbcs.el7
  • M
Improper Authentication

<0:2.9.2-67.GA.jbcs.el7
  • H
Information Exposure

<0:2.9.2-16.GA.jbcs.el7