The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 20, 2015 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 20, 2015 | Jul 20, 2015 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2015-006 | Aug 28, 2015 | Jul 20, 2015 |
| Centos_linux | — | Upgrade mod_proxy_htmlUpgrade httpd-manualUpgrade mod_ldapUpgrade httpd-toolsUpgrade mod_sessionUpgrade mod_sslUpgrade httpdUpgrade httpd-devel | Dec 1, 2016 | Jul 20, 2015 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jul 20, 2015 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jul 15, 2015 |
| Oracle Solaris | — | Upgrade web/server/apache-22 to version 2.2.31-0.175.3.1.0.3.0 on Solaris 11.3Upgrade web/server/apache-22/documentation to version 2.2.31-0.175.3.1.0.3.0 on Solaris 11.3 | May 29, 2017 | Jul 20, 2015 |
| Oracle_linux | — | Upgrade mod_proxy_htmlUpgrade mod_sessionUpgrade httpd24-httpd-develUpgrade httpd-manualUpgrade mod_ldapUpgrade httpd24-httpd-toolsUpgrade httpd24-mod_ldapUpgrade httpd-toolsUpgrade httpd24-httpdUpgrade httpd24-mod_sslUpgrade httpd24-mod_proxy_htmlUpgrade httpdUpgrade httpd24-mod_sessionUpgrade httpd-develUpgrade httpd24-httpd-manualUpgrade mod_ssl | Jul 22, 2024 | Jul 15, 2015 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-mod_auth_kerbUpgrade apache2-example-pagesUpgrade apache2-docUpgrade apache2-mod_security2Upgrade apache2-workerUpgrade apache2Upgrade apache2-develUpgrade apache2-utilsUpgrade apache2-mod_jk | Dec 18, 2015 | Jul 20, 2015 |
| Ubuntu | — | Upgrade apache2.2-bin | Nov 8, 2024 | Jul 20, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub