SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-0053

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors…

MEDIUM 4.3EPSS 82.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 82.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
82.20% probability · 100th percentile
CISA KEV
Not listed
Affected
apache/http server · debian/debian linux · opensuse/opensuse · suse/linux enterprise server · suse/linux enterprise software development kit · redhat/storage · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation · redhat/jboss enterprise web server
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.