Vulnerability Description
mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 2.4.1 |
| Canonical | Ubuntu Linux | 10.04 |
| Fedoraproject | Fedora | 21 |
| Oracle | Enterprise Manager Ops Center | < 12.1.4 |
Related Weaknesses (CWE)
References
- http://advisories.mageia.org/MGASA-2015-0011.htmlThird Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlBroken LinkMailing List
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlBroken LinkMailing List
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159352.htmlMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/11/28/5Mailing ListThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlThird Party Advisory
- http://www.securityfocus.com/bid/73040Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2523-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1174077Issue TrackingPatchThird Party Advisory
- https://github.com/apache/httpd/commit/3f1693d558d0758f829c8b53993f1749ddf6ffcbPatchThird Party Advisory
- https://issues.apache.org/bugzilla/show_bug.cgi?id=57204Issue TrackingVendor Advisory
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cd
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e10
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37
- https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3
FAQ
What is CVE-2014-8109?
CVE-2014-8109 is a vulnerability with a CVSS score of 4.3 (MEDIUM). mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arg...
How severe is CVE-2014-8109?
CVE-2014-8109 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8109?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Canonical Ubuntu Linux, Fedoraproject Fedora, Oracle Enterprise Manager Ops Center.