CVE-2013-4566NSS Project MOD NSS vulnerability

CWE-2646 documents5 sources
Severity
4.0MEDIUMNVD
EPSS
0.1%
top 68.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 14

Description

mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.

CVSS vector

AV:N/AC:H/C:P/I:P/A:NExploitability: 4.9 | Impact: 4.9

Affected Packages1 packages

Also affects: Enterprise Linux 5, 6.0

🔴Vulnerability Details

2
GHSA
GHSA-c4hv-94wj-93p7: mod_nss 12022-05-14
OSV
CVE-2013-4566: mod_nss 12013-12-12

📋Vendor Advisories

1
Red Hat
mod_nss: incorrect handling of NSSVerifyClient in directory context2013-12-03

💬Community

2
Bugzilla
CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context [fedora-all]2013-12-03
Bugzilla
CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context2013-10-08