CVE-2017-3167
—CVSS 3.1
9.8 critical
EPSS
20%p97
Published
()
Modified
Description
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
- Vendors
- apachenetappredhatappledebianoracle
- Products
- http server, clustered data ontap, oncommand unified manager, storagegrid, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, jboss core services, mac os x
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.