PT-2015-1597 · Apache+4 · Apache Http Server+4

Branko Äibej

·

Publicado

2015-06-09

·

Atualizado

2021-06-06

·

CVE-2015-3185

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.x before 2.4.14
Description The issue is related to the ap some auth required function in the Apache HTTP Server, which does not properly consider the difference between authentication and authorization settings. This allows remote attackers to bypass intended access restrictions in certain circumstances, particularly when a module relies on the 2.2 API behavior. The problem arises because the ap some auth required function only checks for the presence of Require lines in the configuration, which can be used for both authentication and authorization. As a result, modules using this API may allow access when they should not.
Recommendations For Apache HTTP Server versions 2.4.x before 2.4.14, consider updating to version 2.4.16 or later, which includes the new ap some authn required API that correctly handles authentication requirements. As a temporary workaround, API users should use the new ap some authn required API instead of ap some auth required to ensure proper authentication checks. At the moment, there is no information about other versions that contain a fix for this vulnerability.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10929
CESA-2015_1667
CVE-2015-3185
DSA-3325-1
DSA-3325-2
MGASA-2015-0281
RHSA-2015:1666
RHSA-2015:1667
RHSA-2015_1667
RHSA-2017:2709
RHSA-2017:2710
SUSE-SU-2015:1851-1
USN-2686-1

Produtos afetados

Apache Http Server
Centos
Red Hat
Suse
Ubuntu