Authentication bypass in Apache HTTP Server - CVE-2017-3167
Published: June 20, 2017 / Updated: July 14, 2017
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to usage of the ap_get_basic_auth_pw() function by third-party modules outside of the authentication phase. A remote attacker can create a specially crafted HTTP request to vulnerable web server, bypass authentication requirements and gain unauthorized access to otherwise protected information.
Affected software
Arch Linux
Amazon Linux AMI
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
Slackware Linux
Fedora
JBoss Core Services
Tenable.sc
apache2 (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
httpd (Red Hat package)
httpd
firefox (Red Hat package)
Dell Secure Connect Gateway
XtremIO XMS
How to mitigate CVE-2017-3167
apache2 (Alpine package) - update to 2.4.26-r0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd (Red Hat package) - update to 2.4.6-40.el7_2.6
httpd - addressed in versions 2.4.26-1.fc24, 2.4.26-1.fc25, 2.4.26-1.fc26, 2.4.27-1.fc25, 2.4.27-2.fc25
XtremIO XMS - update to 6.3.1
firefox (Red Hat package) - update to 115.13.0-3.el8_4
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP server
- Ubuntu update for Apache HTTP Server
- Arch Linux update for apache
- Slackware Linux update for httpd
- Red Hat update for Apache HTTP server
- Red Hat update for Apache HTTP server
- Red Hat update for Apache HTTP server
- Ubuntu update for Apache HTTP Server
- Debian update for apache2
- Gentoo update for Apache
- Amazon Linux AMI update for httpd
- Amazon Linux AMI update for httpd24
- Red Hat update for Apache
- Red Hat update for Apache
- Red Hat update for Apache
- Red Hat update for httpd
- Red Hat update for httpd
- Multiple vulnerabilities in Tenable.sc
- Authentication bypass in apache2 (Alpine package)
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Dell EMC XtremIO
- Red Hat Enterprise Linux 8 update for firefox
- Fedora 25 update for httpd
- Fedora 26 update for httpd
- Fedora 24 update for httpd
- Fedora 25 update for httpd
- Fedora 25 update for httpd
- Red Hat Enterprise Linux 7 update for httpd