Vulnerabilities
Vulnerable Software
Modwsgi:  >> Mod Wsgi  >> 4.2.0  Security Vulnerabilities
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-08-25
mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.
CVSS Score
6.9
EPSS Score
0.001
Published
2014-12-16


Contact Us

Shodan ® - All rights reserved