CyberRota Analysis
AI-GeneratedThe mod_session_cookie module in Apache HTTP Server versions 2.4.0 to 2.4.68 is vulnerable to an exposure of sensitive information, where session cookies may be inadvertently passed to backend servers during internal redirects. This could allow unauthorized actors to access sensitive session data, potentially leading to session hijacking or other malicious activities. Organizations using affected versions of Apache HTTP Server should prioritize patching to mitigate the risk of data exposure.
Original NVD Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Related CVEs
Other vulnerabilities affecting the same vendor(s)