Updated apache-mod_wsgi packages fix security vulnerability
Publication date: 20 Aug 2022Modification date: 20 Aug 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-2255
Description
It was discovered that mod-wsgi did not correctly remove the X-Client-IP header when processing requests from untrusted proxies. A remote attacker could use this issue to pass the header to WSGI applications, contrary to expectations (CVE-2022-2255).
References
SRPMS
8/core
- apache-mod_wsgi-4.6.8-4.1.mga8