CVE-2012-4001
Summary
| CVE | CVE-2012-4001 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-15 10:37:17 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Application | Mod Pagespeed | 0.10.19.1 | All | All | All | |
| Application | Mod Pagespeed | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| mod_pagespeed Security Advisory: Insufficient Hostname Verification - mod_pagespeed — Google Developers | af854a3a-2127-422b-91ae-364da2661108 | developers.google.com | Vendor Advisory |
| mod_pagespeed 0.10.22.6 Security Update. - mod_pagespeed — Google Developers | af854a3a-2127-422b-91ae-364da2661108 | developers.google.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.