In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.2.0 (including) | 2.2.33 (excluding) |
Http_server | Apache | 2.4.0 (including) | 2.4.26 (excluding) |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el6 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-httpd-0:2.4.23-125.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-15.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_1.jbcs.el7 | * |
Red Hat Enterprise Linux 6 | RedHat | httpd-0:2.2.15-60.el6_9.5 | * |
Red Hat Enterprise Linux 6.7 Extended Update Support | RedHat | httpd-0:2.2.15-47.el6_7.5 | * |
Red Hat Enterprise Linux 7 | RedHat | httpd-0:2.4.6-67.el7_4.2 | * |
Red Hat Enterprise Linux 7.2 Extended Update Support | RedHat | httpd-0:2.4.6-40.el7_2.6 | * |
Red Hat Enterprise Linux 7.3 Extended Update Support | RedHat | httpd-0:2.4.6-45.el7_3.5 | * |
Red Hat JBoss Core Services 1 | RedHat | httpd | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | httpd24-httpd-0:2.4.25-9.el6.1 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | httpd24-httpd-0:2.4.25-9.el6.1 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | httpd24-httpd-0:2.4.25-9.el7.1 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | httpd24-httpd-0:2.4.25-9.el7.1 | * |
Apache2 | Ubuntu | devel | * |
Apache2 | Ubuntu | trusty | * |
Apache2 | Ubuntu | upstream | * |
Apache2 | Ubuntu | xenial | * |
Apache2 | Ubuntu | yakkety | * |
Apache2 | Ubuntu | zesty | * |