Vulnerabilities > Modwsgi > MOD Wsgi > 3.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-08-25 | CVE-2022-2255 | Insufficient Verification of Data Authenticity vulnerability in multiple products A vulnerability was found in mod_wsgi. | 7.5 |
2014-12-16 | CVE-2014-8583 | 7PK - Security Features vulnerability in Modwsgi MOD Wsgi mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors. | 6.9 |
2014-05-27 | CVE-2014-0240 | Permissions, Privileges, and Access Controls vulnerability in Modwsgi MOD Wsgi The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes. | 6.2 |