Essentials

Download!

Documentation

Get Support

Get Involved

Subprojects

Miscellaneous

Apache httpd 2.4 vulnerabilities

This page lists all security vulnerabilities fixed in released versions of Apache httpd 2.4. Each vulnerability is given a security impact rating by the Apache security team - please note that this rating may well vary from platform to platform. We also list the versions of Apache httpd the flaw is known to affect, and where a flaw has not been verified list the version with a question mark.

Please note that if a vulnerability is shown below as being fixed in a "-dev" release then this means that a fix has been applied to the development source tree and will be part of an upcoming full release.

This page is created from a database of vulnerabilities originally populated by Apache Week. Please send comments or corrections for these vulnerabilities to the Security Team.

The initial GA release, Apache httpd 2.4.1, includes fixes for all vulnerabilities which have been resolved in Apache httpd 2.2.22 and all older releases. Consult the Apache httpd 2.2 vulnerabilities list for more information.

Fixed in Apache httpd 2.4.4

low: XSS due to unescaped hostnames CVE-2012-3499

Various XSS flaws due to unescaped hostnames and URIs HTML output in mod_info, mod_status, mod_imagemap, mod_ldap, and mod_proxy_ftp.

Acknowledgements: This issue was reported by Niels Heinen of Google

Reported to security team: 11th July 2012
Issue public: 18th February 2013
Update Released: 25th February 2013
Affects: 2.4.3, 2.4.2, 2.4.1

moderate: XSS in mod_proxy_balancer CVE-2012-4558

A XSS flaw affected the mod_proxy_balancer manager interface.

Acknowledgements: This issue was reported by Niels Heinen of google

Reported to security team: 7th October 2012
Issue public: 18th February 2013
Update Released: 25th February 2013
Affects: 2.4.3, 2.4.2, 2.4.1

Fixed in Apache httpd 2.4.3

important: Response mixup when using mod_proxy_ajp or mod_proxy_http CVE-2012-3502

The modules mod_proxy_ajp and mod_proxy_http did not always close the connection to the back end server when necessary as part of error handling. This could lead to an information disclosure due to a response mixup between users.

Issue public: 16th August 2012
Update Released: 21st August 2012
Affects: 2.4.2, 2.4.1

low: XSS in mod_negotiation when untrusted uploads are supported CVE-2012-2687

Possible XSS for sites which use mod_negotiation and allow untrusted uploads to locations which have MultiViews enabled.

Note: This issue is also known as CVE-2008-0455.

Reported to security team: 31st May 2012
Issue public: 13th June 2012
Update Released: 21st August 2012
Affects: 2.4.2, 2.4.1

Fixed in Apache httpd 2.4.2

low: insecure LD_LIBRARY_PATH handling CVE-2012-0883

Insecure handling of LD_LIBRARY_PATH was found that could lead to the current working directory to be searched for DSOs. This could allow a local user to execute code as root if an administrator runs apachectl from an untrusted directory.

Reported to security team: 14th February 2012
Issue public: 2nd March 2012
Update Released: 17th April 2012
Affects: 2.4.1