MEDIUM · 4.3

CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather t...

Vulnerability Description

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CanonicalUbuntu Linux12.04
ApacheHttp Server2.4.0
AppleXcode7.0
AppleMac Os X10.10.4
AppleMac Os X Server5.0.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3185?

CVE-2015-3185 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather t...

How severe is CVE-2015-3185?

CVE-2015-3185 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3185?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Apache Http Server, Apple Xcode, Apple Mac Os X, Apple Mac Os X Server.