A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade httpd | Nov 3, 2017 | Oct 19, 2017 |
| Centos_linux | — | Upgrade httpd-toolsUpgrade httpdUpgrade httpd-manualUpgrade httpd-debuginfoUpgrade mod_sslUpgrade httpd-devel | Oct 23, 2017 | Oct 19, 2017 |
| Oracle_linux | — | Upgrade httpd-toolsUpgrade httpd-manualUpgrade httpdUpgrade mod_sslUpgrade httpd-devel | Oct 20, 2017 | Oct 19, 2017 |
| Redhat_linux | — | Upgrade httpd-manualUpgrade httpdUpgrade httpd-toolsUpgrade httpd-debuginfoUpgrade httpd-develUpgrade mod_ssl | Oct 25, 2017 | Oct 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub