A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | amazon-linux-upgrade-httpd | Nov 3, 2017 | Oct 19, 2017 |
| Centos_linux | — | centos-upgrade-httpdcentos-upgrade-httpd-debuginfocentos-upgrade-httpd-develcentos-upgrade-httpd-manualcentos-upgrade-httpd-toolscentos-upgrade-mod_ssl | Oct 23, 2017 | Oct 19, 2017 |
| Oracle_linux | — | oracle-linux-upgrade-httpdoracle-linux-upgrade-httpd-develoracle-linux-upgrade-httpd-manualoracle-linux-upgrade-httpd-toolsoracle-linux-upgrade-mod-ssl | Oct 20, 2017 | Oct 19, 2017 |
| Redhat_linux | — | redhat-upgrade-httpdredhat-upgrade-httpd-debuginforedhat-upgrade-httpd-develredhat-upgrade-httpd-manualredhat-upgrade-httpd-toolsredhat-upgrade-mod_ssl | Oct 25, 2017 | Oct 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub