ZeroHour

CVE-2017-3167

CVSS 3.1
9.8 critical
EPSS
20%p97
Published
()
Modified
Description

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.

Vendors
apachenetappredhatappledebianoracle
Products
http server, clustered data ontap, oncommand unified manager, storagegrid, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, jboss core services, mac os x
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.