PT-2014-8412 · Apache+2 · Apache Http Server+2

Publicado

2014-11-09

·

Atualizado

2024-06-15

·

CVE-2014-8109

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.3.x and 2.4.x through 2.4.10
Description The issue arises from the mod lua module in the Apache HTTP Server, which does not support an httpd configuration where the same Lua authorization provider is used with different arguments within different contexts. This allows remote attackers to bypass intended access restrictions by leveraging multiple Require directives, potentially leading to unauthorized access to certain directories. For example, a configuration that specifies authorization for one group to access a certain directory and authorization for a second group to access a second directory could be exploited.
Recommendations For Apache HTTP Server versions 2.3.x and 2.4.x through 2.4.10, consider updating the handling of the Require line in mod lua when a LuaAuthzProvider is used in multiple Require directives with different arguments to prevent unexpected authentication rules. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-8109
MGASA-2015-0011
OPENSUSE-SU-2024:10268-1
SUSE-SU-2015:0974-1
USN-2523-1

Produtos afetados

Apache Http Server
Suse
Ubuntu