CVE Vulnerabilities

CVE-2005-2963

Published: Oct 13, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.

Affected Software

NameVendorStart VersionEnd Version
Mod_auth_shadowMod_auth_shadow1.0 (including)1.0 (including)
Mod_auth_shadowMod_auth_shadow1.1 (including)1.1 (including)
Mod_auth_shadowMod_auth_shadow1.2 (including)1.2 (including)
Mod_auth_shadowMod_auth_shadow1.3 (including)1.3 (including)
Mod_auth_shadowMod_auth_shadow1.4 (including)1.4 (including)
Mod_auth_shadowMod_auth_shadow1.5 (including)1.5 (including)
Mod_auth_shadowMod_auth_shadow2.0 (including)2.0 (including)
Mod-auth-shadowUbuntudapper*
Mod-auth-shadowUbuntuedgy*
Mod-auth-shadowUbuntufeisty*

References