The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 6, 2016 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 20, 2016 | Jul 6, 2016 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jul 6, 2016 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jul 5, 2016 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jul 6, 2016 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.0.1 or later | Jun 22, 2018 | Jul 6, 2016 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-lua to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-22 to version 2.2.31-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-22/documentation to version 2.2.31-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-22/module/apache-sed to version 2.2.31-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3 | May 29, 2017 | Jul 6, 2016 |
| Suse | — | Upgrade apache2-utilsUpgrade apache2-docUpgrade apache2-eventUpgrade apache2-example-pagesUpgrade apache2-workerUpgrade apache2Upgrade apache2-preforkUpgrade apache2-devel | Dec 9, 2016 | Jul 6, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub