The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-08-22 12:55
Updated : 2021-06-06 04:15
NVD link : CVE-2012-3502
Mitre link : CVE-2012-3502
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
apache
- http_server