VulnerabilityModified
CVE-2010-1151
Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation…
MEDIUM 6.8EPSS 3.77%
Does this matter?
Lower severity and a low EPSS score (3.77%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.77% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- apache/apache http server
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html
- http://secunia.com/advisories/39823
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:081
- http://www.securityfocus.com/bid/39538
- http://www.vupen.com/english/advisories/2010/0908
- http://www.vupen.com/english/advisories/2010/1148
- https://bugzilla.redhat.com/show_bug.cgi?id=578168Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html
- http://secunia.com/advisories/39823
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:081
- http://www.securityfocus.com/bid/39538
- http://www.vupen.com/english/advisories/2010/0908
- http://www.vupen.com/english/advisories/2010/1148
- https://bugzilla.redhat.com/show_bug.cgi?id=578168Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.