CVE-2012-0053 describes a vulnerability in Apache HTTP Server 2.2.x through 2.2.21, affecting products like Debian, OpenSUSE, Red Hat, and SUSE. This flaw allows remote attackers to disclose HTTPOnly cookie values by crafting long or malformed headers, leading to improper handling during Bad Request error document generation. With a CVSS score of 4.3 (medium severity) and an EPSS score indicating higher than 98% of all CVEs, it has a network attack vector, medium attack complexity, and a partial confidentiality impact. While not actively exploited in the wild and not on the KEV catalog, an exploit (EDB-18442) exists on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.65CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.2.0, < 2.2.22CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.