Skip to main content

Apache HTTPD Client Certificate Authentication Bypassing Vulnerability

Last Update Date: 14 Jul 2016 Release Date: 6 Jul 2016 2798 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability was identified in Apache HTTPD web server. A remote user can bypass client certificate authentication.

Systems using the mod_http2 module and with the h2 and h2c protocols activated in the configuration are affected.


Impact

  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Versions 2.4.18 - 2.4.20

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (2.4.23).

Vulnerability Identifier


Source


Related Link