UBUNTU-CVE-2019-10092
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-10092
UBUNTU-CVE-2019-10092
Summary:
Details: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
References: https://ubuntu.com/security/CVE-2019-10092, https://www.openwall.com/lists/oss-security/2019/08/15/4, https://ubuntu.com/security/notices/USN-4113-1, https://www.cve.org/CVERecord?id=CVE-2019-10092
Affected packages
Package
Name: apache2
Purl: pkg:deb/ubuntu/apache2?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
