Where
-Infinity
0
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

A vulnerability was found in modproxycluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as Require ip IPADDRESS would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

1 / 2
Source: NVD
First published (updated )
Severity
4.3
EPSS
0.07%
Input Validation, CRLF Injection
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

A flaw was found in modproxycluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeenc() function, allows a remote attacker to bypass input validation. By injecting CRLF sequences into the cluster configuration, an attacker can corrupt the response body of INFO endpoint responses. Exploitation requires network access to the MCMP protocol port, but no authentication is needed.

1 / 2
Source: MITRE
First published (updated )
Severity
1

A flaw was found in the modproxycluster in the Apache server. A malicious user can add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting vulnerability. by adding a script on the alias parameter on the URL it adds a new virtual host and adds the script to the cluster-manager page. The impact of this vulnerability is considered as Low as the clustermanager URL should NOT be exposed outside and protected by user/password.

First published (updated )

The modproxycluster module is a plugin for the Apache HTTP Server that provides load-balancer functionality.Bug Fix(es): Rebuild modproxycluster against httpd 2.4.62 (JIRA:RHEL-70140) Rebase modproxycluster to upstream 1.3.22.Final release (JIRA:RHEL-80435) Update deprecated misspeled EnableMCPMReceive directive (JIRA:RHEL-82135)

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )

The modproxycluster module is a plugin for the Apache HTTP Server that provides load-balancer functionality.<br>Security Fix(es):<br><li> modproxycluster: modproxycluster unauthorized MCMP requests (CVE-2024-10306)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

<tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.ppc64le.rpm </td> <td class="checksum">SHA-256: d8fa20c00833ef1936b72c1faca767af862f5d540134f90957b875746f598c76</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.ppc64le.rpm </td> <td class="checksum">SHA-256: 8019380fd2cca55d974d58d108f6b0f1b5a8d086e89a25a9ce386db31ed5c53e</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.ppc64le.rpm </td> <td class="checksum">SHA-256: 58498cbe2a7ee2b90e53ac13b9ab254763f55d8797b38a06a6046436b4d4d070</td> </tr> </tbody>Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.x86_64.rpm </td> <td class="checksum">SHA-256: a97e00322cef26bea7d91bd3bc1211d3657cdc5e4a5744c5b097f7d74a07466e</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.x86_64.rpm </td> <td class="checksum">SHA-256: 6f99daa307b621c4435f15ddc68171f914e9fd052d0b488bf083bd19bc27ccc3</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.x86_64.rpm </td> <td class="checksum">SHA-256: c437c7997251a56a737ca83104757e8a99e1f13cb9b7a5d3183c431859b831fd</td> </tr> </tbody>Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">aarch64</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.aarch64.rpm </td> <td class="checksum">SHA-256: f0b68c21bb568f31b4c93f37766d4db0b044c1aef194ae2bd41423e5de0d6301</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.aarch64.rpm </td> <td class="checksum">SHA-256: 0dbbce8060805694b88e686c5e24deb2457efa7f0efadeb5649c97ae6141aff8</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.aarch64.rpm </td> <td class="checksum">SHA-256: 0e17662c24400d34964d29de8f92403e14fe312f49638026ecbafade5697157a</td> </tr> </tbody>Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">s390x</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.s390x.rpm </td> <td class="checksum">SHA-256: e171e45a96561a58f16296b4a0d5b0ac0f2d972364d1f01518d6a31455797fc6</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.s390x.rpm </td> <td class="checksum">SHA-256: 7edca15f0340634a1cea7694741e43b14fe515edef869dea7b58c66098f8ac6e</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.s390x.rpm </td> <td class="checksum">SHA-256: 5e491f72a50017f9ce7a7f960ee617d8ed0a24d247f4366b90a695886866c3e9</td> </tr> </tbody>Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.x86_64.rpm </td> <td class="checksum">SHA-256: a97e00322cef26bea7d91bd3bc1211d3657cdc5e4a5744c5b097f7d74a07466e</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.x86_64.rpm </td> <td class="checksum">SHA-256: 6f99daa307b621c4435f15ddc68171f914e9fd052d0b488bf083bd19bc27ccc3</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.x86_64.rpm </td> <td class="checksum">SHA-256: c437c7997251a56a737ca83104757e8a99e1f13cb9b7a5d3183c431859b831fd</td> </tr> </tbody>Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">aarch64</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.aarch64.rpm </td> <td class="checksum">SHA-256: f0b68c21bb568f31b4c93f37766d4db0b044c1aef194ae2bd41423e5de0d6301</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.aarch64.rpm </td> <td class="checksum">SHA-256: 0dbbce8060805694b88e686c5e24deb2457efa7f0efadeb5649c97ae6141aff8</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.aarch64.rpm </td> <td class="checksum">SHA-256: 0e17662c24400d34964d29de8f92403e14fe312f49638026ecbafade5697157a</td> </tr> </tbody>Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.ppc64le.rpm </td> <td class="checksum">SHA-256: d8fa20c00833ef1936b72c1faca767af862f5d540134f90957b875746f598c76</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.ppc64le.rpm </td> <td class="checksum">SHA-256: 8019380fd2cca55d974d58d108f6b0f1b5a8d086e89a25a9ce386db31ed5c53e</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.ppc64le.rpm </td> <td class="checksum">SHA-256: 58498cbe2a7ee2b90e53ac13b9ab254763f55d8797b38a06a6046436b4d4d070</td> </tr> </tbody>Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.src.rpm </td> <td class="checksum">SHA-256: 83083fdb33a65ecbf610b870397b6c918c9b5ae943c2fa886b629fe4c48a4fa6</td> </tr> <tr> <th colspan="2">s390x</th> </tr> <tr> <td class="name"> mod_proxy_cluster-1.3.22-1.el9_6.1.s390x.rpm </td> <td class="checksum">SHA-256: e171e45a96561a58f16296b4a0d5b0ac0f2d972364d1f01518d6a31455797fc6</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debuginfo-1.3.22-1.el9_6.1.s390x.rpm </td> <td class="checksum">SHA-256: 7edca15f0340634a1cea7694741e43b14fe515edef869dea7b58c66098f8ac6e</td> </tr> <tr> <td class="name"> mod_proxy_cluster-debugsource-1.3.22-1.el9_6.1.s390x.rpm </td> <td class="checksum">SHA-256: 5e491f72a50017f9ce7a7f960ee617d8ed0a24d247f4366b90a695886866c3e9</td> </tr> </tbody>
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203