CVE Alert: CVE-2024-10306

image 1

Vulnerability Summary: CVE-2024-10306

A vulnerability was found in mod_proxy_cluster. The issue is that the directive should be replaced by the directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

Affected Endpoints:

No affected endpoints listed.

Published Date:

4/23/2025, 10:15:14 AM

⚠️ CVSS Score:

CVSS v3 Score: 5.4 (Medium)

Exploit Status:

Not Exploited

EPS Score: 0.00027 | Ranking EPS: 0.05904

References:

Recommended Action:

No proposed action available. Please refer to vendor documentation for updates.


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.