The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
References
Configurations
Configuration 1 (hide)
|
History
06 Jun 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 Jun 2021, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2012-08-22 19:55
Updated : 2024-02-04 18:16
NVD link : CVE-2012-3502
Mitre link : CVE-2012-3502
CVE.ORG link : CVE-2012-3502
JSON object : View
Products Affected
apache
- http_server
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor