๐Ÿ” CVE Alert

CVE-2024-10306

MEDIUM 5.4

Mod_proxy_cluster: mod_proxy_cluster unauthorized mcmp requests

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

CWE CWE-863
Published Apr 23, 2025
Last Updated Nov 8, 2025
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9.4 Extended Update Support
All versions affected
Red Hat / Red Hat JBoss Core Services
All versions affected
Red Hat / Red Hat JBoss Core Services
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHBA-2025:2973 access.redhat.com: https://access.redhat.com/errata/RHBA-2025:5309 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:9434 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:9466 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:9997 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-10306 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2321302