CVE-2013-2249: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 14.3% chance of exploitation in the next 30 days.

mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.

Affected products

  • Apache HTTP Server: from 2.4.1, up to and including 2.4.4

Published 2013-07-23. Last modified 2026-06-16.