CVE-2014-8109
EPSS 22.0%
描述
mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.
如何修補 CVE-2014-8109
要修補 CVE-2014-8109,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.4.10-9 或更新版本
CVE-2014-8109 正在被利用嗎?
中等 — EPSS 為 22.0%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.4.10-9