← Back to CVE List
Vulnerability Intelligence Report

CVE-2010-2068

mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.

No Active Exploit Signals
CVSS Base Score
5.0
MEDIUM
EPSS Probability:16.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
apache http_server 2.2.9, 2.2.10, 2.2.11, 2.2.12, 2.2.13, 2.2.14, 2.2.15, 2.3.4, 2.3.5
ibm os2 all
microsoft windows all
novell netware all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
16.002%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2010-05-25T00:00:00
Published2010-06-18T16:00:00
Patch Date2010-06-11
Last Updated2024-08-07T02:17:14

LINK COPIED TO CLIPBOARD