REDHAT-BUG-2254128: Low severity apache mod_proxy_cluster vulnerability
A flaw was found in the modproxycluster in the Apache server. A malicious user can add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting vulnerability. by adding a script on the alias parameter on the URL it adds a new virtual host and adds the script to the cluster-manager page. The impact of this vulnerability is considered as Low as the clustermanager URL should NOT be exposed outside and protected by user/password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2254128?
The vulnerability described in REDHAT-BUG-2254128 is a stored cross-site scripting (XSS) vulnerability in the Apache mod_proxy_cluster.
How do I fix REDHAT-BUG-2254128?
To mitigate REDHAT-BUG-2254128, it is recommended to update the Apache mod_proxy_cluster to the latest patched version.
What systems are affected by REDHAT-BUG-2254128?
REDHAT-BUG-2254128 affects systems running the Apache mod_proxy_cluster module.
What are the potential impacts of REDHAT-BUG-2254128?
The potential impacts of REDHAT-BUG-2254128 include unauthorized script execution and data theft through cross-site scripting attacks.
How can REDHAT-BUG-2254128 be exploited?
REDHAT-BUG-2254128 can be exploited by a malicious user who manipulates the 'alias' parameter in the URL to inject a script.