Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Mageia 8 MGASA-2022-0289 Critical Apache-WSGI Header Issue

mageia
Calendar Grey August 20, 2022
Dist Mageia Esm H88
A recent patch for apache-mod_wsgi addresses vulnerabilities that could allow remote adversaries to leverage header flaws in Mageia 8.
It was discovered that mod-wsgi did not correctly remove the X-Client-IP header when processing requests from untrusted proxies

Summary

It was discovered that mod-wsgi did not correctly remove the X-Client-IP header when processing requests from untrusted proxies. A remote attacker could use this issue to pass the header to WSGI applications, contrary to expectations (CVE-2022-2255).

References

- https://bugs.mageia.org/show_bug.cgi?id=30711

- https://ubuntu.com/security/notices/USN-5551-1

- https://www.cve.org/CVERecord?id=CVE-2022-2255

Resolution

SRPMS

- 8/core/apache-mod_wsgi-4.6.8-4.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 20 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0289.html
Type: security
CVE: CVE-2022-2255

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here