A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade httpd | Nov 3, 2017 | Oct 19, 2017 |
| Centos_linux | — | Upgrade httpd-toolsUpgrade httpd-debuginfoUpgrade httpdUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-devel | Oct 23, 2017 | Oct 19, 2017 |
| Oracle_linux | — | Upgrade mod_sslUpgrade httpdUpgrade httpd-develUpgrade httpd-manualUpgrade httpd-tools | Oct 20, 2017 | Oct 19, 2017 |
| Redhat_linux | — | Upgrade httpdUpgrade httpd-debuginfoUpgrade httpd-toolsUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-devel | Oct 25, 2017 | Oct 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub