mod-wsgi@4.2.4 vulnerabilities

Installer for Apache/mod_wsgi.

  • latest version

    5.0.2

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    7 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mod-wsgi package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Access Control Bypass

    Affected versions of this package are vulnerable to Access Control Bypass in src/server/mod_wsgi.c, which fails to strip out X-Client-IP headers from untrusted proxies, allowing attackers to retrieve headers from other IP addresses and send back malicious requests including them.

    How to fix Access Control Bypass?

    Upgrade mod-wsgi to version 4.9.3 or higher.

    [,4.9.3)