GHSA-jm2g-3f56-rvvhMediumCVSS 5.4

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive...

Published
April 23, 2025
Last Modified
June 26, 2026

🔗 CVE IDs covered (1)

📋 Description

A vulnerability was found in mod_proxy_cluster. The issue is that the directive should be replaced by the directive as the former does not restrict IP/host access as Require ip IP_ADDRESS would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

🔗 References (10)