CVE-2018-1283 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Session hijacking |
Description | In Apache httpd 2.2.0 before 2.4.30, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the Apache HTTP Server to pass HTTP header fields, per CGI specifications. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-664 | apache | 2.4.29-1 | 2.4.33-1 | Medium | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
04 Apr 2018 | ASA-201804-4 | AVG-664 | apache | Medium | multiple issues |