Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-9466

Опубликовано: 27 июн. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-9466: mod_proxy_cluster security update (MODERATE)

[1.3.22-1.el10_0.2]

  • Resolves: RHEL-82256 - Update deprecated misspeled EnableMCPMReceive directive

[1.3.22-1.el10_0.1]

  • Resolves: RHEL-80796 - Rebase mod_proxy_cluster to upstream 1.3.22.Final release

[1.3.22-1]

  • Resolves: RHEL-80480 Rebase mod_proxy_cluster to upstream 1.3.22.Final release

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

mod_proxy_cluster

1.3.22-1.el10_0.2

Oracle Linux x86_64

mod_proxy_cluster

1.3.22-1.el10_0.2

Связанные CVE

Связанные уязвимости

CVSS3: 5.4
redhat
5 месяцев назад

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

CVSS3: 5.4
nvd
3 месяца назад

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

CVSS3: 5.4
debian
3 месяца назад

A vulnerability was found in mod_proxy_cluster. The issue is that the ...

CVSS3: 5.4
github
3 месяца назад

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

oracle-oval
около 1 месяца назад

ELSA-2025-9434: mod_proxy_cluster security update (MODERATE)