CVE Vulnerabilities

CVE-2015-3185

Published: Jul 20, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 MODERATE
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical12.04 (including)12.04 (including)
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
Ubuntu_linuxCanonical15.04 (including)15.04 (including)
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-httpd-0:2.4.23-122.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-openssl-1:1.0.2h-14.jbcs.el6*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-httpd-0:2.4.23-122.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-openssl-1:1.0.2h-14.jbcs.el7*
Red Hat Enterprise Linux 7RedHathttpd-0:2.4.6-31.el7_1.1*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-httpd-0:2.4.12-4.el6.2*
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSRedHathttpd24-httpd-0:2.4.12-4.el6.2*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHathttpd24-httpd-0:2.4.12-4.el6.2*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-httpd-0:2.4.12-6.el7.1*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHathttpd24-httpd-0:2.4.12-6.el7.1*
Text-Only JBCSRedHat*
Text-Only JBCSRedHat*
Apache2Ubuntudevel*
Apache2Ubuntuesm-infra-legacy/trusty*
Apache2Ubuntutrusty*
Apache2Ubuntutrusty/esm*
Apache2Ubuntuupstream*
Apache2Ubuntuutopic*
Apache2Ubuntuvivid*

References