Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6710

Опубликовано: 12 дек. 2023
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:modcluster:mod_proxy_cluster:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.0063
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 1 года назад

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.

CVSS3: 5.4
debian
больше 1 года назад

A flaw was found in the mod_proxy_cluster in the Apache server. This i ...

CVSS3: 3.5
github
больше 1 года назад

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page. The impact of this vulnerability is considered as Low, as the cluster_manager URL should not be exposed outside and is protected by user/password.

oracle-oval
больше 1 года назад

ELSA-2024-2387: mod_jk and mod_proxy_cluster security update (MODERATE)

EPSS

Процентиль: 69%
0.0063
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79