Apache HTTPD Client Certificate Authentication Bypassing Vulnerability
Last Update Date:
14 Jul 2016
Release Date:
6 Jul 2016
3620
Views
RISK: Medium Risk
TYPE: Servers - Web Servers
A vulnerability was identified in Apache HTTPD web server. A remote user can bypass client certificate authentication.
Systems using the mod_http2 module and with the h2 and h2c protocols activated in the configuration are affected.
Impact
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Versions 2.4.18 - 2.4.20
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (2.4.23).
Vulnerability Identifier
Source
Related Link
Share with