Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
BID:35840
Info
Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
| Bugtraq ID: | 35840 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2009 12:00AM |
| Updated: | Jul 28 2009 05:05PM |
| Credit: | ithilgore |
| Vulnerable: |
Apache Apache 2.2.2 |
| Not Vulnerable: | |
Discussion
Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
Apache is prone to an authentication-bypass vulnerability because it fails to properly enforce access restrictions on certain requests to a site that requires authentication.
Very little technical information is currently available. We will update this BID as more information emerges.
An attacker can exploit this issue to gain access to protected resources, which may allow the attacker to obtain sensitive information or launch further attacks.
Apache 2.2.2 is vulnerable; other versions may also be affected.
Apache is prone to an authentication-bypass vulnerability because it fails to properly enforce access restrictions on certain requests to a site that requires authentication.
Very little technical information is currently available. We will update this BID as more information emerges.
An attacker can exploit this issue to gain access to protected resources, which may allow the attacker to obtain sensitive information or launch further attacks.
Apache 2.2.2 is vulnerable; other versions may also be affected.
Exploit / POC
Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: Some reports indicate that Apache 2.2.11 is no longer affected by this issue.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: Some reports indicate that Apache 2.2.11 is no longer affected by this issue.
References
Apache HTTP Server HTTP-Basic Authentication Bypass Vulnerability
References:
References:
- Apache 2.2 HTTP Basic Auth bypass (Solar Designer)
- Apache Homepage (Apache Software Foundation)
- Ncrack: buggy web server response / authentication (ithilgore)
- Re: Apache 2.2 HTTP Basic Auth bypass (ithilgore)
- Re: Apache 2.2 HTTP Basic Auth bypass (Solar Designer)
- Re: Status Report #14 of 17 (ithilgore)