PT-2004-2733 · Apache · Apache+1
Published
2004-03-20
·
Updated
2021-06-06
·
CVE-2004-1834
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache versions 2.0 through 2.0.49
Description
The issue concerns the storage of client headers, including authentication information, on the hard disk by the mod disk cache module. This could potentially allow local users to gain access to sensitive information, such as proxy authentication credentials and Basic Authentication passwords, for cached objects.
Recommendations
For Apache versions 2.0 through 2.0.49, consider disabling the mod disk cache module to prevent the storage of sensitive authentication information on disk until a proper fix is available. Restrict access to the cached objects to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Apache Http Server