CVE-2016-4979
published 2016-07-06CVE-2016-4979: The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for…
PriorityP359high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
18.80%
97.0th percentile
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | httpd | — | — |
| debian | apache2 | < apache2 2.4.23-1 (bookworm) | apache2 2.4.23-1 (bookworm) |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r48c-7gpg-9q4x: The Apache HTTP Server 2
ghsa_unreviewed·2022-05-13
CVE-2016-4979 [HIGH] CWE-284 GHSA-r48c-7gpg-9q4x: The Apache HTTP Server 2
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
OSV
CVE-2016-4979: The Apache HTTP Server 2
osv·2016-07-06·CVSS 7.5
CVE-2016-4979 [HIGH] CVE-2016-4979: The Apache HTTP Server 2
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
Red Hat
httpd: X509 client certificate authentication bypass using HTTP/2
vendor_redhat·2016-07-05·CVSS 7.5
CVE-2016-4979 [HIGH] CWE-287 httpd: X509 client certificate authentication bypass using HTTP/2
httpd: X509 client certificate authentication bypass using HTTP/2
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
A flaw was found in the way httpd performed client authentication using X.509 client certificates. When the HTTP/2 protocol was enabled, a remote attacker could use this flaw to access resources protected by certificate authentication without providing a valid client certificate.
Package: httpd (Red Hat Directory Server 8) - Not affected
Package: httpd (Red Hat En
Debian
CVE-2016-4979: apache2 - The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are ena...
vendor_debian·2016·CVSS 7.5
CVE-2016-4979 [HIGH] CVE-2016-4979: apache2 - The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are ena...
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
Scope: local
bookworm: resolved (fixed in 2.4.23-1)
bullseye: resolved (fixed in 2.4.23-1)
forky: resolved (fixed in 2.4.23-1)
sid: resolved (fixed in 2.4.23-1)
trixie: resolved (fixed in 2.4.23-1)
Apache
Apache httpd: CVE-2016-4979
vendor_apache·CVSS 7.5
CVE-2016-4979 [HIGH] Apache httpd: CVE-2016-4979
Apache httpd: CVE-2016-4979
For configurations enabling support for HTTP/2, SSL client certificate validation was not enforced if configured, allowing clients unauthorized access to protected resources over HTTP/2. This issue affected releases 2.4.18 and 2.4.20 only. Acknowledgements: This issue was reported by Erki Aring. Reported to security team 2016-06-30 Issue public 2016-07-05 Update 2.4.23 released 2016-07-05 Affects 2.4.20, 2.4.18
Severity: high
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4979 httpd: X509 Client certificate based authentication can be bypassed when HTTP/2 is used [fedora-all]
bugzilla·2016-07-06·CVSS 7.5
CVE-2016-4979 [HIGH] CVE-2016-4979 httpd: X509 Client certificate based authentication can be bypassed when HTTP/2 is used [fedora-all]
CVE-2016-4979 httpd: X509 Client certificate based authentication can be bypassed when HTTP/2 is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2016-4979 httpd: X509 client certificate authentication bypass using HTTP/2
bugzilla·2016-07-04·CVSS 7.5
CVE-2016-4979 [HIGH] CVE-2016-4979 httpd: X509 client certificate authentication bypass using HTTP/2
CVE-2016-4979 httpd: X509 client certificate authentication bypass using HTTP/2
The Apache HTTPD web server (from 2.4.18/r1715255 up to 2.4.23/r1750779) did not validate a X509 client certificate correctly when HTTP/2 is used to access a resource.
As a result - a resource thought to be secure and requiring a valid client certificate - would be accessible without authentication provided that the mod_http2 was loaded, h2 or h2c activated, that that the browser used the HTTP/2 protocol and it would do more than one request over a given connection. A third party can gain access to resources on the web server without the requisite credentials. This can then lead to unauthorised disclosure of information.
This issue has been fixed in version 2.4.23 (r1750779).
As a temporary workaround - HTT
http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://packetstormsecurity.com/files/137771/Apache-2.4.20-X509-Authentication-Bypass.htmlhttp://seclists.org/fulldisclosure/2016/Jul/11http://www.apache.org/dist/httpd/CHANGES_2.4http://www.openwall.com/lists/oss-security/2016/07/05/5http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.securityfocus.com/bid/91566http://www.securitytracker.com/id/1036225https://access.redhat.com/errata/RHSA-2016:1420https://github.com/apache/httpd/commit/2d0e4eff04ea963128a41faaef21f987272e05a2https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.gentoo.org/glsa/201610-02https://security.netapp.com/advisory/ntap-20180601-0001/http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://packetstormsecurity.com/files/137771/Apache-2.4.20-X509-Authentication-Bypass.htmlhttp://seclists.org/fulldisclosure/2016/Jul/11http://www.apache.org/dist/httpd/CHANGES_2.4http://www.openwall.com/lists/oss-security/2016/07/05/5http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.htmlhttp://www.securityfocus.com/bid/91566http://www.securitytracker.com/id/1036225https://access.redhat.com/errata/RHSA-2016:1420https://github.com/apache/httpd/commit/2d0e4eff04ea963128a41faaef21f987272e05a2https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.gentoo.org/glsa/201610-02https://security.netapp.com/advisory/ntap-20180601-0001/
2016-07-06
Published