CVE Database
/

CVE-2015-3185

Back to search

CVE-2015-3185

Published: Jul 20, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2015:1684
vendor-advisory
x_refsource_SUSE
RHSA-2015:1667
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2015-09-16-2
vendor-advisory
x_refsource_APPLE
RHSA-2017:2709
vendor-advisory
x_refsource_REDHAT
RHSA-2015:1666
vendor-advisory
x_refsource_REDHAT
1032967
vdb-entry
x_refsource_SECTRACK
USN-2686-1
vendor-advisory
x_refsource_UBUNTU
APPLE-SA-2015-08-13-2
vendor-advisory
x_refsource_APPLE
75965
vdb-entry
x_refsource_BID
DSA-3325
vendor-advisory
x_refsource_DEBIAN
RHSA-2016:2957
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2710
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2015-09-16-4
vendor-advisory
x_refsource_APPLE
RHSA-2017:2708
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now