{"api_version":"1","generated_at":"2026-07-23T12:46:19+00:00","cve":"CVE-2010-1151","urls":{"html":"https://cve.report/CVE-2010-1151","api":"https://cve.report/api/cve/CVE-2010-1151.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-1151","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-1151"},"summary":{"title":"CVE-2010-1151","description":"Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.","state":"PUBLISHED","assigner":"redhat","published_at":"2010-04-20 16:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-362","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 11 Update: mod_auth_shadow-2.2-8.fc11","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39823","name":"http://secunia.com/advisories/39823","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for mod_auth_shadow - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:081","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:081","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advisories | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 12 Update: mod_auth_shadow-2.2-8.fc12","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/39538","name":"http://www.securityfocus.com/bid/39538","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apache mod_auth_shadow Race Condition Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=578168","name":"https://bugzilla.redhat.com/show_bug.cgi?id=578168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Bug 578168 – CVE-2010-1151 mod_auth_shadow: bad wait(2) call causes randomized authorization behaviour","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/0908","name":"http://www.vupen.com/english/advisories/2010/0908","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1148","name":"http://www.vupen.com/english/advisories/2010/1148","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-1151","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1151","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"1151","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"apache_http_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T01:14:06.289Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2010-0908","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0908"},{"name":"39538","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/39538"},{"name":"MDVSA-2010:081","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:081"},{"name":"FEDORA-2010-6359","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html"},{"name":"39823","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39823"},{"name":"FEDORA-2010-6323","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=578168"},{"name":"ADV-2010-1148","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1148"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-04-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-04-30T09:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"ADV-2010-0908","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0908"},{"name":"39538","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/39538"},{"name":"MDVSA-2010:081","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:081"},{"name":"FEDORA-2010-6359","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html"},{"name":"39823","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39823"},{"name":"FEDORA-2010-6323","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=578168"},{"name":"ADV-2010-1148","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1148"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2010-1151","datePublished":"2010-04-20T16:00:00.000Z","dateReserved":"2010-03-29T00:00:00.000Z","dateUpdated":"2024-08-07T01:14:06.289Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-04-20 16:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-362","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:apache_http_server:*:*:*:*:*:*:*:*","matchCriteriaId":"180ABE44-C676-44DC-9461-6B70A055D50D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"1151","Ordinal":"1","Title":"CVE-2010-1151","CVE":"CVE-2010-1151","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"1151","Ordinal":"1","NoteData":"Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.","Type":"Description","Title":"CVE-2010-1151"},{"CveYear":"2010","CveId":"1151","Ordinal":"2","NoteData":"2010-04-20","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"1151","Ordinal":"3","NoteData":"2010-04-30","Type":"Other","Title":"Modified"}]}}}