Description
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2785 Vulnerability (CVE-2019-2785)
Oracle JRE CVE-2023-21939 Vulnerability (CVE-2023-21939)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-6433)
PHP NULL Pointer Dereference Vulnerability (CVE-2016-7131)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2006-6943)