The Apache webserver module mod_status provides information on an Apache server's activity and performance. The module uses a publicly accessible webpage located at /server-status to provide real-time traffic logs in addition to host information including CPU usage, current HTTP requests, client IP addresses, requested paths, and processed virtual hosts. Such information could give a potential attacker information to aid further attacks and could disclose sensitive traffic information. No authentication is required to exploit this information disclosure vulnerability.
If required, update Apache's configuration file(s) to either disable mod_status or ensure that access is limited to valid users / hosts.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →