Advisories ยป MGASA-2022-0289

Updated apache-mod_wsgi packages fix security vulnerability

Publication date: 20 Aug 2022
Modification date: 20 Aug 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-2255

Description

It was discovered that mod-wsgi did not correctly remove the X-Client-IP
header when processing requests from untrusted proxies. A remote attacker
could use this issue to pass the header to WSGI applications, contrary to
expectations (CVE-2022-2255).
                

References

SRPMS

8/core