Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.

Project Subscriptions

Vendors Products
Http Server Subscribe
Canonical Subscribe
Ubuntu Linux Subscribe
Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-731-1 Apache vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=123376588623823&w=2 cve-icon cve-icon
http://secunia.com/advisories/31026 cve-icon cve-icon
http://secunia.com/advisories/32222 cve-icon cve-icon
http://secunia.com/advisories/33797 cve-icon cve-icon
http://secunia.com/advisories/34219 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200807-06.xml cve-icon cve-icon
http://securityreason.com/securityalert/3523 cve-icon cve-icon
http://support.apple.com/kb/HT3216 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0966.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/486169/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/494858/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/27236 cve-icon cve-icon
http://www.securityfocus.com/bid/31681 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-731-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2780 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0320 cve-icon cve-icon
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8371 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-6420 cve-icon
History

Wed, 28 May 2025 14:45:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 04:30:00 +0000


Tue, 27 Aug 2024 12:30:00 +0000

Type Values Removed Values Added
Title mod_proxy_balancer CSRF mod_proxy_balancer: mod_proxy_balancer CSRF

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T16:02:36.869Z

Reserved: 2007-12-17T00:00:00

Link: CVE-2007-6420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2008-01-12T00:46:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-6420

cve-icon Redhat

Severity : Low

Publid Date: 2008-09-01T00:00:00Z

Links: CVE-2007-6420 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses