CVE-2019-10092: Apache HTTP Server

Medium severity, CVSS 6.1. EPSS: 81.5% chance of exploitation in the next 30 days.

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

Affected products

  • Apache HTTP Server: from 2.4.0, up to and including 2.4.39
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 30 only
  • Netapp Clustered Data Ontap: up to and including 9.5; version 9.6 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Communications Element Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle Secure Global Desktop: version 5.4 only; version 5.5 only
  • Red Hat Software Collection: version 1.0 only

Published 2019-09-26. Last modified 2026-06-17.