mod_wsgi module before 3.4 for Apache, when used in...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 3, 2024
Description
Published by the National Vulnerability Database
Dec 9, 2019
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Apr 3, 2024
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
References