Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12607
HistoryJan 15, 2019 - 9:19 a.m.

Access Restriction Bypass

2019-01-1509:19:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.004 Low

EPSS

Percentile

72.6%

httpd is vulnerable to authorization bypass. It was discovered that in httpd 2.4, the internal API function ap_some_auth_required() could incorrectly indicate that a request was authenticated even when no authentication was used. An httpd module using this API function could consequently allow access that should have been denied.

References