ZeroHour

CVE-2018-1283

CVSS 3.0
5.3 medium
EPSS
10%p95
Published
()
Modified
Description

In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the Apache HTTP Server to pass HTTP header fields, per CGI specifications.

Vendors
apachedebiancanonicalnetappredhat
Products
http server, debian linux, ubuntu linux, santricity cloud connector, storage automation store, storagegrid, clustered data ontap, enterprise linux
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.