mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.101
EPSS Ranking 92.8%