ALPINE-CVE-2018-1283
Dashboard / Vulnerabilities / ALPINE-CVE-2018-1283
Summary:
Details: In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the Apache HTTP Server to pass HTTP header fields, per CGI specifications.
Affected packages
Package
Name: apache2
Purl: pkg:apk/alpine/apache2?arch=source
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.4.33-r0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
