Bugzilla – Bug 1201634
VUL-0: CVE-2022-2255: apache2-mod_wsgi-python3,apache2-mod_wsgi: trusted proxy header filtering bypass
Last modified: 2022-12-14 17:34:07 UTC
rh#2100563 A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy (trusted proxies are configured via the WSGITrustedProxies directive) allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing. References: https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L13940-L13941 https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L14046-L14082 References: https://bugzilla.redhat.com/show_bug.cgi?id=2100563 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-2255
Affected: - SUSE:SLE-12-SP1:Update/apache2-mod_wsgi - SUSE:SLE-12-SP4:Update:Products:Cloud9:Update/apache2-mod_wsgi (wontfix) - SUSE:SLE-15:Update/apache2-mod_wsgi - SUSE:SLE-15-SP4:Update/apache2-mod_wsgi - SUSE:SLE-15:Update/apache2-mod_wsgi-python3
Fix: https://github.com/GrahamDumpleton/mod_wsgi/commit/af3c0c2736bc0b0b01fa0f0aad3c904b7fa9c751
(In reply to Carlos López from comment #1) > Affected: > - SUSE:SLE-12-SP1:Update/apache2-mod_wsgi > - SUSE:SLE-15:Update/apache2-mod_wsgi > - SUSE:SLE-15-SP4:Update/apache2-mod_wsgi > - SUSE:SLE-15:Update/apache2-mod_wsgi-python3 Any news @cloud-bugs? :)
SUSE-SU-2022:4010-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1201634 CVE References: CVE-2022-2255 JIRA References: Sources used: openSUSE Leap 15.4 (src): apache2-mod_wsgi-4.7.1-150400.3.3.1 SUSE Linux Enterprise Module for Public Cloud 15-SP4 (src): apache2-mod_wsgi-4.7.1-150400.3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:4013-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1201634 CVE References: CVE-2022-2255 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 8 (src): apache2-mod_wsgi-4.4.13-3.3.1 SUSE OpenStack Cloud 8 (src): apache2-mod_wsgi-4.4.13-3.3.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): apache2-mod_wsgi-4.4.13-3.3.1 SUSE Linux Enterprise Module for Public Cloud 12 (src): apache2-mod_wsgi-4.4.13-3.3.1 HPE Helion Openstack 8 (src): apache2-mod_wsgi-4.4.13-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:4488-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1201634 CVE References: CVE-2022-2255 JIRA References: Sources used: openSUSE Leap 15.4 (src): apache2-mod_wsgi-python3-4.5.18-150000.4.6.1 openSUSE Leap 15.3 (src): apache2-mod_wsgi-4.5.18-150000.4.6.1, apache2-mod_wsgi-python3-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for Server Applications 15-SP4 (src): apache2-mod_wsgi-python3-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for Server Applications 15-SP3 (src): apache2-mod_wsgi-python3-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3 (src): apache2-mod_wsgi-python3-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2 (src): apache2-mod_wsgi-python3-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1 (src): apache2-mod_wsgi-python3-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for Public Cloud 15-SP3 (src): apache2-mod_wsgi-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for Public Cloud 15-SP2 (src): apache2-mod_wsgi-4.5.18-150000.4.6.1 SUSE Linux Enterprise Module for Public Cloud 15-SP1 (src): apache2-mod_wsgi-4.5.18-150000.4.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.