VYPR
Unrated severityNVD Advisory· Published Mar 20, 2004· Updated Apr 16, 2026

CVE-2004-1834

CVE-2004-1834

Description

mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Apache mod_disk_cache in versions 2.0 to 2.0.49 stores client authentication headers in plaintext on disk, allowing local users to obtain sensitive credentials.

Vulnerability

Apache mod_disk_cache in versions 2.0 through 2.0.49 writes client request headers, including Proxy-Authorization and Authorization headers, to disk cache files. For Basic Authentication, passwords are stored in plaintext [2].

Exploitation

An attacker with local access to the file system where cache files are stored (e.g., the default cache directory) can read these files. No authentication or user interaction is required beyond local access [2].

Impact

Successful exploitation leads to disclosure of authentication credentials, including usernames and plaintext passwords for HTTP Basic Authentication, potentially allowing the attacker to impersonate legitimate users.

Mitigation

No official patch was included in Apache 2.0.49. Red Hat issued an advisory (RHSA-2004-562) [3] providing a fix. Administrators should upgrade to a patched version or disable mod_disk_cache if not required. Note that mod_disk_cache was experimental and later superseded.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

21
  • Apache/HTTP Server20 versions
    cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.41:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.42:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.43:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.44:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.45:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*
  • Range: >=2.0, <=2.0.49

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

25

News mentions

0

No linked articles in our index yet.