CVE-2013-2249 describes a vulnerability in the mod_session_dbd module of Apache HTTP Server versions prior to 2.4.5, where session save operations proceed without properly checking the dirty flag or the need for a new session ID, leading to unspecified impact. This vulnerability carries a CVSS score of 7.5, indicating a high severity with a network-based attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impacts. Despite its high FAUCET Risk Score of 94/100 and some community discussion, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.1, <= 2.4.4CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_session_dbd session fixation flaw
Jul 22, 2013Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project