Medium severity5.4NVD Advisory· Published Apr 23, 2025· Updated Jun 30, 2026
CVE-2024-10306
CVE-2024-10306
Description
A vulnerability was found in mod_proxy_cluster. The issue is that the directive should be replaced by the directive as the former does not restrict IP/host access as Require ip IP_ADDRESS would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
8- access.redhat.com/errata/RHBA-2025:2973nvd
- access.redhat.com/errata/RHBA-2025:5309nvd
- access.redhat.com/errata/RHSA-2025:9434nvd
- access.redhat.com/errata/RHSA-2025:9466nvd
- access.redhat.com/errata/RHSA-2025:9997nvd
- access.redhat.com/security/cve/CVE-2024-10306nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/modcluster/mod_proxy_cluster/pull/309nvd
News mentions
0No linked articles in our index yet.