Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-8109

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.266
EPSS Ranking 96.0%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2014-8109


Contact Us

Shodan ® - All rights reserved