The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
References
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 02:11
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2012-08-22 19:55
Updated : 2024-02-28 12:00
NVD link : CVE-2012-3502
Mitre link : CVE-2012-3502
CVE.ORG link : CVE-2012-3502
JSON object : View
Products Affected
apache
- http_server
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor