CVE-2018-1283 log
| Source | 
							
  | 
					
| Severity | Medium | 
| Remote | Yes | 
| Type | Session hijacking | 
| Description | In Apache httpd 2.2.0 before 2.4.30, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the Apache HTTP Server to pass HTTP header fields, per CGI specifications.  | 
					
| Group | Package | Affected | Fixed | Severity | Status | Ticket | 
|---|---|---|---|---|---|---|
| AVG-664 | apache | 2.4.29-1 | 2.4.33-1 | Medium | Fixed | 
| Date | Advisory | Group | Package | Severity | Type | 
|---|---|---|---|---|---|
| 04 Apr 2018 | ASA-201804-4 | AVG-664 | apache | Medium | multiple issues |