Description
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1900-1 | apache2 security update |
Debian DLA |
DLA-1900-2 | apache2 regression update |
Debian DSA |
DSA-4509-1 | apache2 security update |
Debian DSA |
DSA-4509-3 | apache2 security update |
Ubuntu USN |
USN-4113-1 | Apache HTTP Server vulnerabilities |
References
History
No history.
Subscriptions
Apache
Subscribe
Http Server
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Netapp
Subscribe
Clustered Data Ontap
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Oracle
Subscribe
Communications Element Manager
Subscribe
Enterprise Manager Ops Center
Subscribe
Secure Global Desktop
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Rhel Software Collections
Subscribe
Software Collection
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T22:10:09.500Z
Reserved: 2019-03-26T00:00:00.000Z
Link: CVE-2019-10092
No data.
Status : Modified
Published: 2019-09-26T16:15:10.613
Modified: 2024-11-21T04:18:23.233
Link: CVE-2019-10092
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN