Debian Mod-Wsgi vulnerabilities

4 known vulnerabilities affecting debian/mod-wsgi.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2022-2255HIGHCVSS 7.5fixed in mod-wsgi 4.9.0-1.1 (bookworm)2022
CVE-2022-2255 [HIGH] CVE-2022-2255: mod-wsgi - A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed fro... A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing. Scope: local bookworm: resolved (fixed in 4.9.0-1.1) bullseye: resolved (fixed in 4.7.1-3+deb11u1) forky: resolved (fixed
debian
CVE-2014-0242HIGHCVSS 7.5PoCfixed in mod-wsgi 3.4-3 (bookworm)2014
CVE-2014-0242 [HIGH] CVE-2014-0242: mod-wsgi - mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow r... mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread. Scope: local bookworm: resolved (fixed in 3.4-3) bullseye: resolved (fixed in 3.4-3) forky: resolved (fixed in 3.4
debian
CVE-2014-0240MEDIUMCVSS 6.2fixed in mod-wsgi 3.5-1 (bookworm)2014
CVE-2014-0240 [MEDIUM] CVE-2014-0240: mod-wsgi - The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not... The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes. Scope: local bookworm: resolved (fixed in 3.5-1) bullseye: resolved (fixed in 3.5-1) forky: resolved (fi
debian
CVE-2014-8583MEDIUMCVSS 6.9fixed in mod-wsgi 4.2.7-1 (bookworm)2014
CVE-2014-8583 [MEDIUM] CVE-2014-8583: mod-wsgi - mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not... mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors. Scope: local bookworm: resolved (fixed in 4.2.7-1) bullseye: resolved (fixed in 4.2.7-1) forky: resolved (fixed in 4.2.7-1) sid: resolved (fixed in 4.2.7-1)
debian