modwsgi mod_wsgi 4.2.4

CPE Details

modwsgi mod_wsgi 4.2.4
4.2.4
2014-12-17
15h53 +00:00
2015-01-17
13h06 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:modwsgi:mod_wsgi:4.2.4:*:*:*:*:*:*:*

Informations

Vendor

modwsgi

Product

mod_wsgi

Version

4.2.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-2255 2022-08-25 15h26 +00:00 A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
7.5
High
CVE-2014-8583 2014-12-16 17h00 +00:00 mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.
6.9