RHSA-2024:1316Vendor advisory
https://access.redhat.com/errata/RHSA-2024:1316 CVE-2023-6710
MEDIUM
Mod_cluster/mod_proxy_cluster: stored cross site scripting
Record summary
CVE-2023-6710 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page.
Description source: CVE List
Exploitation context
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
JBoss Core Services for RHEL 8Browse Red Hat / JBoss Core Services for RHEL 8jbcs-httpd24-mod_proxy_clusterDefault status: affected | CVE List | 0:1.3.20-3.el8jbcs to < * | unaffected |
JBoss Core Services on RHEL 7Browse Red Hat / JBoss Core Services on RHEL 7jbcs-httpd24-mod_proxy_clusterDefault status: affected | CVE List | 0:1.3.20-3.el7jbcs to < * | unaffected |
Default status: affected | CVE List | 0:1.3.20-1.el9_4 to < * | unaffected |
Default status: affected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Proofs of concept
3Catalogued exploits
ExploitDBApache mod_proxy_cluster 1.2.6 - Stored XSSExploitDB exploitby Mohamed Mounir BoudjemaNot analyzed1 file
Repository PoCs
GitHubDedSec-47/Metasploit-Exploits-CVE-2023-6710Repository PoCby DedSec-47Stars: 1Not analyzed3 files
GitHubDedSec-47/CVE-2023-6710Repository PoCby DedSec-47Stars: 2Not analyzed4 files
References
6RHSA-2024:1317Vendor advisory
https://access.redhat.com/errata/RHSA-2024:1317 RHSA-2024:2387Vendor advisory
https://access.redhat.com/errata/RHSA-2024:2387 access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2023-6710 RHBZ#2254128issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2254128 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6710