Information Exposure Affecting apache/httpd package, versions [2.2.9,2.3.5]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Not Defined
EPSS
1.03% (84th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-APACHEHTTPD-3007243
  • published12 Jan 2022
  • disclosed18 Jun 2010
  • creditUnknown

Introduced: 18 Jun 2010

CVE-2010-2068  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

There is no fixed version for apache/httpd.

Overview

Affected versions of this package are vulnerable to Information Exposure mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.

References

CVSS Scores

version 3.1