PT-2015-1597 · Apache+4 · Apache Http Server+4

Branko Äibej

·

Published

2015-06-09

·

Updated

2021-06-06

·

CVE-2015-3185

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.x before 2.4.14
Description The issue is related to the ap some auth required function in the Apache HTTP Server, which does not properly consider the difference between authentication and authorization settings. This allows remote attackers to bypass intended access restrictions in certain circumstances, particularly when a module relies on the 2.2 API behavior. The problem arises because the ap some auth required function only checks for the presence of Require lines in the configuration, which can be used for both authentication and authorization. As a result, modules using this API may allow access when they should not.
Recommendations For Apache HTTP Server versions 2.4.x before 2.4.14, consider updating to version 2.4.16 or later, which includes the new ap some authn required API that correctly handles authentication requirements. As a temporary workaround, API users should use the new ap some authn required API instead of ap some auth required to ensure proper authentication checks. At the moment, there is no information about other versions that contain a fix for this vulnerability.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-10929
CESA-2015_1667
CVE-2015-3185
DSA-3325-1
DSA-3325-2
MGASA-2015-0281
RHSA-2015:1666
RHSA-2015:1667
RHSA-2015_1667
RHSA-2017:2709
RHSA-2017:2710
SUSE-SU-2015:1851-1
USN-2686-1

Affected Products

Apache Http Server
Centos
Red Hat
Suse
Ubuntu