CVE-2009-1191
published 2009-04-23CVE-2009-1191: mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client…
PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
12.38%
95.8th percentile
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.11-4 (bookworm) | apache2 2.2.11-4 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h7v8-q79w-9jq6: mod_proxy_ajp
ghsa_unreviewed·2022-05-02
CVE-2009-1191 [MEDIUM] CWE-20 GHSA-h7v8-q79w-9jq6: mod_proxy_ajp
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
OSV
CVE-2009-1191: mod_proxy_ajp
osv·2009-04-23·CVSS 5.0
CVE-2009-1191 [MEDIUM] CVE-2009-1191: mod_proxy_ajp
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-06-11·CVSS 4.3
CVE-2009-1195 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
Matthew Palmer discovered an underflow flaw in apr-util as included in
Apache. An attacker could cause a denial of service via application crash
in Apache using a crafted SVNMasterURI directive, .htaccess file, or when
using mod_apreq2. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-0023)
Sander de Boer discovered that mod_proxy_ajp would reuse connections when
a client closed a connection without sending a request body. A remote
attacker could exploit this to obtain sensitive response data. This issue
only affected Ubuntu 9.04. (CVE-2009-1191)
Jonathan Peatfield discovered that Apache did not process Includes options
correctly. With certain configurations of Options and AllowOverride, a
local attacker could use an .hta
Red Hat
httpd mod_proxy_ajp information disclosure
vendor_redhat·2009-04-21·CVSS 5.0
CVE-2009-1191 [MEDIUM] httpd mod_proxy_ajp information disclosure
httpd mod_proxy_ajp information disclosure
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
Debian
CVE-2009-1191: apache2 - mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 all...
vendor_debian·2009·CVSS 5.0
CVE-2009-1191 [MEDIUM] CVE-2009-1191: apache2 - mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 all...
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
Scope: local
bookworm: resolved (fixed in 2.2.11-4)
bullseye: resolved (fixed in 2.2.11-4)
forky: resolved (fixed in 2.2.11-4)
sid: resolved (fixed in 2.2.11-4)
trixie: resolved (fixed in 2.2.11-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1191 httpd mod_proxy_ajp information disclosure
bugzilla·2009-05-26·CVSS 5.0
CVE-2009-1191 [MEDIUM] CVE-2009-1191 httpd mod_proxy_ajp information disclosure
CVE-2009-1191 httpd mod_proxy_ajp information disclosure
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #496801: CVE-2009-1191 httpd mod_proxy_ajp information disclosure
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available and only close this bug once all affected Fedora versions are fixed.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?bugs=496801
Discussion:
httpd 2
Bugzilla
CVE-2009-1191 httpd mod_proxy_ajp information disclosure
bugzilla·2009-04-21·CVSS 2.6
CVE-2009-1191 [LOW] CVE-2009-1191 httpd mod_proxy_ajp information disclosure
CVE-2009-1191 httpd mod_proxy_ajp information disclosure
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1191 to the following vulnerability:
mod_proxy_ajp in Apache httpd 2.2.11 allows remote attackers to obtain sensitive information via an arbitrary request from a HTTP client, in opportunistic circumstances involving a request from a different client that included a Content-Length header but no POST data.
This is similar to the issue CVE-2008-5519 in mod_jk
Prior to httpd 2.2.11 this was not an issue. It was an issue
due to http://svn.apache.org/viewvc?view=rev&revision=711779
Patch will be applied to 2.2.12:
http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/
Discussion:
The patch is available for download from the following location:
https://support.re
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://osvdb.org/53921http://secunia.com/advisories/34827http://secunia.com/advisories/35395http://secunia.com/advisories/35721http://security.gentoo.org/glsa/glsa-200907-04.xmlhttp://support.apple.com/kb/HT3937http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=766938&r2=767089http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/PR46949.diffhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:102http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlhttp://www.securityfocus.com/bid/34663http://www.securitytracker.com/id?1022264http://www.ubuntu.com/usn/usn-787-1http://www.vupen.com/english/advisories/2009/1147http://www.vupen.com/english/advisories/2009/3184https://exchange.xforce.ibmcloud.com/vulnerabilities/50059https://issues.apache.org/bugzilla/show_bug.cgi?id=46949https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8261http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://osvdb.org/53921http://secunia.com/advisories/34827http://secunia.com/advisories/35395http://secunia.com/advisories/35721http://security.gentoo.org/glsa/glsa-200907-04.xmlhttp://support.apple.com/kb/HT3937http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=766938&r2=767089http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/PR46949.diffhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:102http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.htmlhttp://www.securityfocus.com/bid/34663http://www.securitytracker.com/id?1022264http://www.ubuntu.com/usn/usn-787-1http://www.vupen.com/english/advisories/2009/1147http://www.vupen.com/english/advisories/2009/3184https://exchange.xforce.ibmcloud.com/vulnerabilities/50059https://issues.apache.org/bugzilla/show_bug.cgi?id=46949https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8261
2009-04-23
Published