Back

MEDIUM

mod_proxy_balancer: mod_proxy_balancer CSRF

Published Jan 12, 2008

Description

Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.

Affected products

Remediation

Red Hat statement

mod_proxy_balancer is shipped in Red Hat Enterprise Linux 5 and Red Hat Application Stack v2. We do not plan on correcting this issue as it poses a very low security risk: The balancer manager is not enabled by default, the user targeted by the CSRF would need to be authenticated, and the consequences of an exploit would be limited to a web server denial of service.

Metrics

Weaknesses (1)

References (35)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 12, 2008
Updated Aug 7, 2024
Reserved Dec 17, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Sep 1, 2008