You are here

CVE-2007-6420

Vincent (CVE) Danen's picture
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.

Details Source

Mitre

Statement

mod_proxy_balancer is shipped in Red Hat Enterprise Linux 5 and Red Hat Application Stack v2. We do not plan on correcting this issue as it poses a very low security risk: The balancer manager is not enabled by default, the user targeted by the CSRF would need to be authenticated, and the consequences of an exploit would be limited to a web server denial of service.

Public Date

2008-09-01 00:00:00

Impact

Low

Bugzilla

CVE-2007-6420 mod_proxy_balancer CSRF

Bugzilla ID

471 009

CVSS Status

draft

Red Hat Security Errata

Platform Errata Release Date
Red Hat Application Stack v2 for Enterprise Linux (v.5) RHSA-2008:0966 2008-12-04

CWE

CWE-352