VDB

DEBIAN-CVE-2018-1283

DEBIAN-CVE-2018-1283 PUBLISHED CVSS 5.300000190734863 MEDIUM

In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs, since the prefix "HTTP_" is also used by the Apache HTTP Server to pass HTTP header fields, per CGI specifications.

Risk Scores

CVSS v3.0
5.300000190734863
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:12apache20, 0, 0
Debian:11apache20, 0, 0
Debian:14apache20, 0, 0
Debian:13apache20, 0, 0

Timeline

  • Mar 26, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›