PT-2019-3893 · Apache+7 · Apache Http Server+7

Published

2019-07-09

·

Updated

2025-09-29

·

CVE-2019-10092

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.0 through 2.4.39
Description A limited cross-site scripting issue was reported affecting the mod proxy error page in Apache HTTP Server. This issue could allow an attacker to cause the link on the error page to be malformed, pointing to a page of their choice, but only where a server was set up with proxying enabled and misconfigured to display the Proxy Error page. The vulnerability is related to the failure to protect the structure of web pages, which could allow a remote attacker to redirect users to a malicious site using a specially crafted web page.
Recommendations For Apache HTTP Server versions 2.4.0 through 2.4.39, consider disabling the mod proxy module until a patch is available to prevent exploitation of the limited cross-site scripting issue in the mod proxy error page. Restrict access to the mod proxy error page to minimize the risk of exploitation. As a temporary workaround, ensure proper configuration of proxying to avoid displaying the Proxy Error page.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019_2925
ALSA-2020:4751
ALSA-2020_4751
ALSA-2025_16880
ALT-PU-2019-2471
ALT-PU-2019-3402
BDU:2019-04286
CESA-2020_4751
CVE-2019-10092
DLA-1900-1
DLA-1900-2
DSA-4509-1
DSA-4509-2
DSA-4509-3
ELSA-2020-4751
MGASA-2019-0407
OPENSUSE-SU-2019:2051-1
OPENSUSE-SU-2019_2051-1
OPENSUSE-SU-2024:10623-1
RHSA-2019:4126
RHSA-2020:1337
RHSA-2020:4751
RHSA-2020_4751
RLSA-2020:4751
RLSA-2020_4751
SUSE-SU-2019:2237-1
SUSE-SU-2019:2329-1
SUSE-SU-2019_2237-1
SUSE-SU-2019_2329-1
SUSE-SU-2021:0779-1
SUSE-SU-2021:2004-1
SUSE-SU-2021_0779-1
SUSE-SU-2021_2004-1
USN-4113-1
USN-4113-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Centos
Red Hat
Rocky Linux
Suse
Ubuntu