CVE-2012-3502 is a vulnerability in the mod_proxy_ajp and mod_proxy_http modules of Apache HTTP Server 2.4.x before 2.4.3. It allows remote attackers to obtain sensitive information by improperly handling back-end connections, leading to responses intended for one client being sent to another. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and potential for partial confidentiality impact. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.0:*:*:*:*:*:*:* | ||
2.4.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:* | ||
2.4.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025mod_proxy_http): Information disclosure due improper management of back end server connection close within error handling
Aug 16, 2012Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project