Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache 安全漏洞
Vulnerability Description
Apache是一款广泛使用的开放源代码WEB服务程序。 Apache 2.x mod_ssl中存在限制绕过漏洞,成功利用这个漏洞的攻击者可以绕过安全策略,无需有效的客户端证书便可访问受限制的资源。如果mod_ssl配置为同SSLVerifyClient指令使用的话,就会出现这个漏洞。
CVSS Information
N/A
Vulnerability Type
N/A