Description
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.
Remediation
References
Related Vulnerabilities
Django Incorrect Default Permissions Vulnerability (CVE-2020-24584)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4066)
Ruby on Rails CVE-2022-23634 Vulnerability (CVE-2022-23634)
WordPress Plugin Personalized WooCommerce Cart Page Cross-Site Request Forgery (2.4)
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38845)