← Back

CVE-2014-8109

nvd nist
Published: Dec 29, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.

Affected (17)

Show all products
1 product
Http Server
1 product
Ubuntu Linux
1 product
Fedora
1 product
Enterprise Manager Ops Center
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 2.4.10
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4.6
Version 2.4.7
Version 2.4.9
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 12.04
Version 14.04
Version 14.10
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 21
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Before 12.1.4
Version 12.2.0
Version 12.2.1
Version 12.3.0

References (50)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken LinkMailing List
Source: secalert@redhat.com
Broken LinkMailing List
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.