Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Mod_Auth_Shadow 认证绕过漏洞
Vulnerability Description
mod-auth-shadow是Apache HTTP Server用于认证/etc/shadow文件的模块。 mod_auth_shadow module 1.0,1.5 到 2.0如果启用了AuthShadow的话,则mod_auth_shadow模块会对所有使用require group指令的位置都使用shadow认证,即使已经指定了其他的认证机制,这个允许远程认证用户绕过安全限制。
CVSS Information
N/A
Vulnerability Type
N/A