mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2013-07-23 17:20
Updated : 2021-06-06 11:15
NVD link : CVE-2013-2249
Mitre link : CVE-2013-2249
JSON object : View
Products Affected
apache
- http_server
juniper
- junos_space
CWE
