mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.2.11 (including) | 2.2.11 (including) |
JBEWS 1.0 for RHEL 4 | RedHat | httpd22-0:2.2.10-16.1.ep5.el4 | * |
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | RedHat | httpd-0:2.2.10-4.ep5.el5 | * |
Apache2 | Ubuntu | jaunty | * |
Apache2 | Ubuntu | upstream | * |