Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-5fv4-m5x3-j32p

около 4 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

EPSS: Средний
ubuntu логотип

CVE-2015-3185

около 11 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2015-3185

около 11 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS3: 3.7
EPSS: Средний
nvd логотип

CVE-2015-3185

около 11 лет назад

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2015-3185

около 11 лет назад

The ap_some_auth_required function in server/request.c in the Apache H ...

CVSS2: 4.3
EPSS: Средний
fstec логотип

BDU:2015-10929

около 11 лет назад

Уязвимость веб-сервера Apache HTTP Server, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 4.3
EPSS: Средний
oracle-oval логотип

ELSA-2015-1667

почти 11 лет назад

ELSA-2015-1667: httpd security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1851-1

почти 11 лет назад

Security update for apache2

EPSS: Низкий
oracle-oval логотип

ELSA-2015-1666

больше 10 лет назад

ELSA-2015-1666: httpd24-httpd security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5fv4-m5x3-j32p

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

19%
Средний
около 4 лет назад
ubuntu логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
19%
Средний
около 11 лет назад
redhat логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS3: 3.7
19%
Средний
около 11 лет назад
nvd логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS2: 4.3
19%
Средний
около 11 лет назад
debian логотип
CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache H ...

CVSS2: 4.3
19%
Средний
около 11 лет назад
fstec логотип
BDU:2015-10929

Уязвимость веб-сервера Apache HTTP Server, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 4.3
19%
Средний
около 11 лет назад
oracle-oval логотип
ELSA-2015-1667

ELSA-2015-1667: httpd security update (MODERATE)

почти 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:1851-1

Security update for apache2

почти 11 лет назад
oracle-oval логотип
ELSA-2015-1666

ELSA-2015-1666: httpd24-httpd security update (MODERATE)

больше 10 лет назад

Уязвимостей на страницу