ECHO-310b-3edb-2ba5

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-310b-3edb-2ba5.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-310b-3edb-2ba5
Upstream
Withdrawn
2026-07-13T15:45:01Z
Published
2026-05-28T15:55:26Z
Modified
2026-07-13T16:30:03Z
Summary
mod_usertrack in Apache 1.3.11 through 1.3.20 generates predictable session IDs (host IP, system time, PID), which "allows local users to obtain session IDs and bypass authentication when these session IDs are used for authentication". Red Hat states "This is not a security issue. The mod_usertrack cookies are not designed to be used for authentication." NVD affected range is 1.3.11-1.3.20, far below the shipped 2.4.68. Debian: unimportant. https://security-tracker.debian.org/tracker/CVE-2001-1534
Details
References

Affected packages

Echo / apache2

Package

Name
apache2
Purl
pkg:deb/echo/apache2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.68-1~deb13u1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-310b-3edb-2ba5.json"