{"id":"ECHO-310b-3edb-2ba5","summary":"mod_usertrack in Apache 1.3.11 through 1.3.20 generates predictable\nsession IDs (host IP, system time, PID), which \"allows local users to\nobtain session IDs and bypass authentication when these session IDs are\nused for authentication\". Red Hat states \"This is not a security issue.\nThe mod_usertrack cookies are not designed to be used for\nauthentication.\" NVD affected range is 1.3.11-1.3.20, far below the\nshipped 2.4.68. Debian: unimportant.\nhttps://security-tracker.debian.org/tracker/CVE-2001-1534\n","modified":"2026-07-13T16:30:03.936840551Z","published":"2026-05-28T15:55:26.609Z","withdrawn":"2026-07-13T15:45:01.813Z","upstream":["CVE-2001-1534"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2001-1534"}],"affected":[{"package":{"name":"apache2","ecosystem":"Echo","purl":"pkg:deb/echo/apache2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.68-1~deb13u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-310b-3edb-2ba5.json"}}],"schema_version":"1.9.0"}