Back

MEDIUM

httpd: limited cross-site scripting in mod_proxy error page

Published Sep 26, 2019

Description

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

Affected products

Remediation

Red Hat mitigation

This flaw is only exploitable if Proxy* directives are used in Apache httpd configuration. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Proxy' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_proxy.html

Metrics

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 26, 2019
Updated Aug 4, 2024
Reserved Mar 26, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 14, 2019