CVE-2007-6420
published 2008-01-12CVE-2007-6420: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
9.11%
94.8th percentile
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.9-1 (bookworm) | apache2 2.2.9-1 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6p65-8p9q-94p9: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2
ghsa_unreviewed·2022-05-01
CVE-2007-6420 [MEDIUM] CWE-352 GHSA-6p65-8p9q-94p9: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
OSV
CVE-2007-6420: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2
osv·2008-01-12·CVSS 4.3
CVE-2007-6420 [MEDIUM] CVE-2007-6420: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-03-10·CVSS 4.3
CVE-2007-6203 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the method specifier header from
an HTTP request when it is returned in an error message, which could result in
browsers becoming vulnerable to cross-site scripting attacks when processing the
output. With cross-site scripting vulnerabilities, if a user were tricked into
viewing server output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain. This issue only affected Ubuntu 6.06 LTS and
7.10. (CVE-2007-6203)
It was discovered that Apache was vulnerable to a cross-site request forgery
(CSRF) in the mod_proxy_balancer balancer manager. If an Apache administrator
were t
Red Hat
mod_proxy_balancer: mod_proxy_balancer CSRF
vendor_redhat·2008-09-01·CVSS 4.3
CVE-2007-6420 [MEDIUM] CWE-352 mod_proxy_balancer: mod_proxy_balancer CSRF
mod_proxy_balancer: mod_proxy_balancer CSRF
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
A cross-site request forgery issue was found in the mod_proxy_balancer module. A remote attacker could cause a denial of service if mod_proxy_balancer is enabled and an authenticated
user is targeted. (CVE-2007-6420)
Statement: mod_proxy_balancer is shipped in Red Hat Enterprise Linux 5 and Red Hat Application Stack v2. We do not plan on correcting this issue as it poses a very low security risk: The balancer manager is not enabled by default, the user targeted by the CSRF would need to be authenticated, and the consequences of an exploit would be limited
Debian
CVE-2007-6420: apache2 - Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_p...
vendor_debian·2007·CVSS 4.3
CVE-2007-6420 [MEDIUM] CVE-2007-6420: apache2 - Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_p...
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.2.9-1)
bullseye: resolved (fixed in 2.2.9-1)
forky: resolved (fixed in 2.2.9-1)
sid: resolved (fixed in 2.2.9-1)
trixie: resolved (fixed in 2.2.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-6420 mod_proxy_balancer: mod_proxy_balancer CSRF
bugzilla·2008-11-11·CVSS 4.3
CVE-2007-6420 [MEDIUM] CVE-2007-6420 mod_proxy_balancer: mod_proxy_balancer CSRF
CVE-2007-6420 mod_proxy_balancer: mod_proxy_balancer CSRF
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6420 to the following vulnerability:
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
Discussion:
mod_proxy_balancer is shipped in Red Hat Enterprise Linux 5 and Red Hat Application Stack v2.
We do not plan on correcting this issue in Red Hat Enterprise Linux 5 as it poses a very low security risk: The balancer manager is not enabled by default, the user targeted by the CSRF would need to be authenticated, and the consequences of an exploit would be limited to a web server denial of service.
We plan on updating to a new
Bugzilla
Security: CVE-2008-2364, CVE-2007-6420: Apache 2.2.9 released, offers significant performance/security improvements
bugzilla·2008-07-04·CVSS 4.3
CVE-2008-2364 [MEDIUM] Security: CVE-2008-2364, CVE-2007-6420: Apache 2.2.9 released, offers significant performance/security improvements
Security: CVE-2008-2364, CVE-2007-6420: Apache 2.2.9 released, offers significant performance/security improvements
Description of problem: Fedora 8 and 9 use Apache 2.2.8. There are significant
improvements in 2.2.9 that I have seen on Windows that should also improve the
performance on Fedora.
Version-Release number of selected component (if applicable): 2.2.9
How reproducible: Always
Additional info: See http://www.apache.org/dist/httpd/CHANGES_2.2.9 for list
of improvements. This also fixes CVE-2007-6420 and CVE-2008-2364, the latter
probably was the one that fixed my high memory usage problem and caused an
unintentional DOS on a slow Windows server running 2.2.8.
Discussion:
Additionally, there are two significant security flaws with this, so much so
that I decided to change
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://marc.info/?l=bugtraq&m=123376588623823&w=2http://secunia.com/advisories/31026http://secunia.com/advisories/32222http://secunia.com/advisories/33797http://secunia.com/advisories/34219http://security.gentoo.org/glsa/glsa-200807-06.xmlhttp://securityreason.com/securityalert/3523http://support.apple.com/kb/HT3216http://www.redhat.com/support/errata/RHSA-2008-0966.htmlhttp://www.securityfocus.com/archive/1/486169/100/0/threadedhttp://www.securityfocus.com/archive/1/494858/100/0/threadedhttp://www.securityfocus.com/bid/27236http://www.securityfocus.com/bid/31681http://www.ubuntu.com/usn/USN-731-1http://www.vupen.com/english/advisories/2008/2780http://www.vupen.com/english/advisories/2009/0320https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8371http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://marc.info/?l=bugtraq&m=123376588623823&w=2http://secunia.com/advisories/31026http://secunia.com/advisories/32222http://secunia.com/advisories/33797http://secunia.com/advisories/34219http://security.gentoo.org/glsa/glsa-200807-06.xmlhttp://securityreason.com/securityalert/3523http://support.apple.com/kb/HT3216http://www.redhat.com/support/errata/RHSA-2008-0966.htmlhttp://www.securityfocus.com/archive/1/486169/100/0/threadedhttp://www.securityfocus.com/archive/1/494858/100/0/threadedhttp://www.securityfocus.com/bid/27236http://www.securityfocus.com/bid/31681http://www.ubuntu.com/usn/USN-731-1http://www.vupen.com/english/advisories/2008/2780http://www.vupen.com/english/advisories/2009/0320https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8371
2008-01-12
Published