PT-2004-2733 · Apache · Apache+1
Publicado
2004-03-20
·
Atualizado
2021-06-06
·
CVE-2004-1834
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache versions 2.0 through 2.0.49
Description
The issue concerns the storage of client headers, including authentication information, on the hard disk by the mod disk cache module. This could potentially allow local users to gain access to sensitive information, such as proxy authentication credentials and Basic Authentication passwords, for cached objects.
Recommendations
For Apache versions 2.0 through 2.0.49, consider disabling the mod disk cache module to prevent the storage of sensitive authentication information on disk until a proper fix is available. Restrict access to the cached objects to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache
Apache Http Server