CVE-2024-10306

Executive Summary

CVE-2024-10306 exposes Apache mod_proxy_cluster to unauthorized MCMP requests due to improper use of instead of . Attackers with host access can add, remove, or update backend nodes, potentially redirecting traffic or disrupting load balancing. The flaw does not allow arbitrary code execution but enables configuration manipulation, compromising availability and integrity of the cluster.


Authoritative CVE Metadata - CVSS Base Score: 5.4 (MEDIUM) - Published: 2025-04-23T10:15:14.330 - Last Modified: 2026-10-06T18:16:40.613

Original Description: A vulnerability was found in mod_proxy_cluster. The issue is that the directive should be replaced by the directive as the former does not restrict IP/host access as Require ip IP_ADDRESS would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.

"Those who are free of resentful thoughts surely find peace."

— Buddha
Source: NVD