Search CVE reports


Toggle filters

161 – 170 of 498 results


CVE-2023-28625

Medium priority
Vulnerable

mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a...

1 affected package

libapache2-mod-auth-openidc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache2-mod-auth-openidc Not affected Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2023-26464

Low priority
Ignored

** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap...

1 affected package

apache-log4j1.2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache-log4j1.2 — Not affected Not affected Ignored Ignored
Show less packages

CVE-2023-27522

Medium priority
Fixed

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — Fixed Fixed Not affected
Show less packages

CVE-2023-25690

Medium priority

Some fixes available 12 of 13

Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-36659

Medium priority
Needs evaluation

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE:...

1 affected package

libapache-session-browseable-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-session-browseable-perl Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-36658

Medium priority
Fixed

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can,...

1 affected package

libapache-session-ldap-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-session-ldap-perl — — Not affected Fixed Fixed
Show less packages

CVE-2023-24021

Medium priority

Some fixes available 4 of 5

Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read...

1 affected package

modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity-apache Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-48279

Medium priority

Some fixes available 5 of 9

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to...

2 affected packages

modsecurity, modsecurity-apache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
modsecurity Not affected Not affected Needs evaluation Needs evaluation Not in release
modsecurity-apache Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-37436

Medium priority

Some fixes available 12 of 13

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose,...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-36760

Medium priority

Some fixes available 12 of 13

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects...

1 affected package

apache2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Fixed Fixed Fixed Fixed Fixed
Show less packages