PublicDateAtUSN: 2019-08-14 Candidate: CVE-2019-10092 PublicDate: 2019-09-26 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10092 https://www.openwall.com/lists/oss-security/2019/08/15/4 https://ubuntu.com/security/notices/USN-4113-1 Description: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed. Ubuntu-Description: Notes: sbeattie> all 2.4.x up to 2.4.41 sbeattie> first two upstream patches are hardening Bugs: Priority: low Discovered-by: Matei "Mal" Badanoiu Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_apache2: upstream: https://github.com/apache/httpd/commit/b5aa97e7c9792ba31055507eaf9a54e1fbb17464 upstream: https://github.com/apache/httpd/commit/7106a941f8086e06d4c1b26a8dd6d2a4695eee5a upstream: https://github.com/apache/httpd/commit/0522155a5a0fb5ba3b5716a63a3c2253aa74085e upstream_apache2: released (2.4.41-1) precise/esm_apache2: not-affected trusty_apache2: ignored (out of standard support) trusty/esm_apache2: needs-triage xenial_apache2: released (2.4.18-2ubuntu3.12) esm-infra/xenial_apache2: released (2.4.18-2ubuntu3.12) bionic_apache2: released (2.4.29-1ubuntu4.10) disco_apache2: released (2.4.38-2ubuntu2.2) eoan_apache2: not-affected (2.4.41-1ubuntu1) focal_apache2: not-affected (2.4.41-1ubuntu1) groovy_apache2: not-affected (2.4.41-1ubuntu1) hirsute_apache2: not-affected (2.4.41-1ubuntu1) impish_apache2: not-affected (2.4.41-1ubuntu1) jammy_apache2: not-affected (2.4.41-1ubuntu1) devel_apache2: not-affected (2.4.41-1ubuntu1)