PT-2014-8412 · Apache+2 · Apache Http Server+2

Published

2014-11-09

·

Updated

2024-06-15

·

CVE-2014-8109

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.3.x and 2.4.x through 2.4.10
Description The issue arises from the mod lua module in the Apache HTTP Server, which does not support an httpd configuration where the same Lua authorization provider is used with different arguments within different contexts. This allows remote attackers to bypass intended access restrictions by leveraging multiple Require directives, potentially leading to unauthorized access to certain directories. For example, a configuration that specifies authorization for one group to access a certain directory and authorization for a second group to access a second directory could be exploited.
Recommendations For Apache HTTP Server versions 2.3.x and 2.4.x through 2.4.10, consider updating the handling of the Require line in mod lua when a LuaAuthzProvider is used in multiple Require directives with different arguments to prevent unexpected authentication rules. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8109
MGASA-2015-0011
OPENSUSE-SU-2024:10268-1
SUSE-SU-2015:0974-1
USN-2523-1

Affected Products

Apache Http Server
Suse
Ubuntu