Security features bypass in mod_wsgi - CVE-2022-2255
Published: August 9, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to mod_wsgi does not correctly remove the X-Client-IP header when processing requests from untrusted proxies. A remote attacker can pass a trusted proxy IP address via the X-Client-IP HTTP header and bypass implemented security restrictions.
Affected software
python39-wcwidth
python39-PyMySQL
python39-toml
python39-pluggy
python39-Cython
python39-wheel-wheel
python39-wheel
python39-iniconfig
python39-scipy
python39-pysocks
python39-py
python39-cffi
python39-six
python39-numpy-doc
python39-numpy-f2py
python39-numpy
python39-urllib3
python39-pyparsing
python39-pybind11-devel
python39-pybind11
python39-psycopg2-tests
python39-psycopg2-doc
python39-psycopg2
python39-idna
python39-pycparser
python39-requests
python39-chardet
python39-cryptography
python39
python39-rpm-macros
python39-test
python39-tkinter
python39-libs
python39-idle
python39-devel
python39-debug
python39-ply
apache2-mod_wsgi-debuginfo
apache2-mod_wsgi
apache2-mod_wsgi-debugsource
libapache2-mod-wsgi (Ubuntu package)
libapache2-mod-wsgi-py3 (Ubuntu package)
apache2-mod_wsgi-python3-debugsource
apache2-mod_wsgi-python3-debuginfo
apache2-mod_wsgi-python3
mod_wsgi-debuginfo
python3-mod_wsgi
mod_wsgi-debugsource
python39-lxml
python39-mod_wsgi
python39-pyyaml
python39-psutil
python39-pytest
python39-more-itertools
python39-pip-wheel
python39-pip
python39-attrs
python39-packaging
python39-setuptools
python39-setuptools-wheel
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Proxy
SUSE Enterprise Storage
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
Ubuntu
openEuler
How to mitigate CVE-2022-2255
python39-wcwidth - update to 0.2.5-3
python39-PyMySQL - update to 0.10.1-2
python39-toml - update to 0.10.1-5
python39-pluggy - update to 0.13.1-3
python39-Cython - update to 0.29.21-5
python39-wheel-wheel - update to 0.35.1-4
python39-wheel - update to 0.35.1-4
python39-iniconfig - update to 1.1.1-2
python39-scipy - update to 1.5.4-5.0.1
python39-pysocks - update to 1.7.1-4
python39-py - update to 1.10.0-1
python39-cffi - update to 1.14.3-2
python39-six - update to 1.15.0-3
python39-numpy-doc - update to 1.19.4-3.0.1
python39-numpy-f2py - update to 1.19.4-3.0.1
python39-numpy - update to 1.19.4-3.0.1
python39-urllib3 - update to 1.25.10-5
python39-pyparsing - update to 2.4.7-5
python39-pybind11-devel - update to 2.7.1-1
python39-pybind11 - update to 2.7.1-1
python39-psycopg2-tests - update to 2.8.6-3.0.1
python39-psycopg2-doc - update to 2.8.6-3.0.1
python39-psycopg2 - update to 2.8.6-3.0.1
python39-idna - update to 2.10-4
python39-pycparser - update to 2.20-3
python39-requests - update to 2.25.0-3
python39-chardet - update to 3.0.4-19
python39-cryptography - update to 3.3.1-3
python39 - update to 3.9.20-1.0.1
python39-rpm-macros - update to 3.9.20-1.0.1
python39-test - update to 3.9.20-1.0.1
python39-tkinter - update to 3.9.20-1.0.1
python39-libs - update to 3.9.20-1.0.1
python39-idle - update to 3.9.20-1.0.1
python39-devel - update to 3.9.20-1.0.1
python39-debug - update to 3.9.20-1.0.1
python39-ply - update to 3.11-10
apache2-mod_wsgi-debuginfo - addressed in versions 4.4.13-3.3.1, 4.5.18-150000.4.6.1, 4.7.1-150400.3.3.1
apache2-mod_wsgi - addressed in versions 4.4.13-3.3.1, 4.5.18-150000.4.6.1, 4.7.1-150400.3.3.1
apache2-mod_wsgi-debugsource - addressed in versions 4.4.13-3.3.1, 4.5.18-150000.4.6.1, 4.7.1-150400.3.3.1
libapache2-mod-wsgi (Ubuntu package) - addressed in versions 4.5.17-1ubuntu1.1, 4.6.8-1ubuntu3.1
libapache2-mod-wsgi-py3 (Ubuntu package) - addressed in versions 4.5.17-1ubuntu1.1, 4.6.8-1ubuntu3.1, 4.9.0-1ubuntu0.1
apache2-mod_wsgi-python3-debugsource - update to 4.5.18-150000.4.6.1
apache2-mod_wsgi-python3-debuginfo - update to 4.5.18-150000.4.6.1
apache2-mod_wsgi-python3 - update to 4.5.18-150000.4.6.1
mod_wsgi - update to 4.6.4-3
mod_wsgi-debuginfo - update to 4.6.4-3
python3-mod_wsgi - update to 4.6.4-3
mod_wsgi-debugsource - update to 4.6.4-3
python39-lxml - update to 4.6.5-1
python3-mod_wsgi - update to 4.7.1-3.el7
python39-mod_wsgi - update to 4.7.1-7
python39-pyyaml - update to 5.4.1-1
python39-psutil - update to 5.8.0-4.0.1
python39-pytest - update to 6.0.2-2.0.1
python39-more-itertools - update to 8.5.0-2
python39-pip-wheel - update to 20.2.4-9
python39-pip - update to 20.2.4-9
python39-attrs - update to 20.3.0-2
python39-packaging - update to 20.4-4
python39-setuptools - update to 50.3.2-6
python39-setuptools-wheel - update to 50.3.2-6
External References
Related Security Bulletins
- Security features bypass in mod_wsgi
- Ubuntu update for mod-wsgi
- SUSE update for apache2-mod_wsgi
- SUSE update for apache2-mod_wsgi
- SUSE update for apache2-mod_wsgi
- openEuler update for mod_wsgi
- Fedora EPEL 7 update for python3-mod_wsgi
- Red Hat Enterprise Linux 8 update for the python39:3.9 module
- Anolis OS update for python39:3.9 module