CVE-2007-6420Cross-Site Request Forgery in Apache Http Server

Severity
4.3MEDIUMNVD
EPSS
5.5%
top 9.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 1

Description

Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapache/http_server7 versions+6

Also affects: Ubuntu Linux 6.06, 7.10, 8.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6p65-8p9q-94p9: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 22022-05-01
CVEList
CVE-2007-6420: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 22008-01-12
OSV
CVE-2007-6420: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 22008-01-12

📋Vendor Advisories

3
Ubuntu
Apache vulnerabilities2009-03-10
Red Hat
mod_proxy_balancer: mod_proxy_balancer CSRF2008-09-01
Debian
CVE-2007-6420: apache2 - Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_p...2007

💬Community

2
Bugzilla
CVE-2007-6420 mod_proxy_balancer: mod_proxy_balancer CSRF2008-11-11
Bugzilla
Security: CVE-2008-2364, CVE-2007-6420: Apache 2.2.9 released, offers significant performance/security improvements2008-07-04
CVE-2007-6420 — Cross-Site Request Forgery in Apache | cvebase