CVE-2019-10092: XSS
A cross-site scripting vulnerability was found in Apache httpd, affecting the modproxy error page. Under certain circumstances, a crafted link could inject content into the HTML displayed in the error page, potentially leading to client-side exploitation.
Other sources
A limited cross-site scripting issue was reported affecting the modproxy error page. An attacker could cause the link on the error page to be malfomed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
— Red Hat
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the modproxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.
Affected Software
Remediation
Information
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-10092?
The severity of CVE-2019-10092 is medium with a CVSS score of 6.1.
How does CVE-2019-10092 affect Apache httpd?
CVE-2019-10092 affects Apache httpd versions 2.4.0-2.4.39, causing a limited cross-site scripting issue in the mod_proxy error page.
How can an attacker exploit CVE-2019-10092?
An attacker can exploit CVE-2019-10092 by causing the link on the error page to be malformed and redirecting to a page of their choice.
Which software versions are affected by CVE-2019-10092?
CVE-2019-10092 affects Apache HTTP Server versions 2.4.0-2.4.39.
Where can I find more information about CVE-2019-10092?
You can find more information about CVE-2019-10092 on Bugzilla Red Hat, Apache HTTP Server security vulnerabilities page, and Red Hat support policy updates.