CVE-2014-8109

Apache HTTP Server 2.3.x and 2.4.x <= 2.4.10 - Incorrect Authorization via mod_lua Module

Title source: llm
STIX 2.1

Description

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.

References (25)

Core 25
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1174077
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2523-1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/11/28/5
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73040
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2015-0011.html
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159352.html
Issue Tracking, Vendor Advisory x_refsource_confirm
https://issues.apache.org/bugzilla/show_bug.cgi?id=57204
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT205031
Third Party Advisory x_refsource_confirm
https://support.apple.com/HT205219

Scores

EPSS 0.1172
EPSS Percentile 93.8%

Details

CWE
CWE-863
Status published
Products (17)
apache/http_server 2.4.1
apache/http_server 2.4.2
apache/http_server 2.4.3
apache/http_server 2.4.4
apache/http_server 2.4.6
apache/http_server 2.4.7
apache/http_server 2.4.9
apache/http_server 2.4.10
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
... and 7 more
Published Dec 29, 2014
Tracked Since Feb 18, 2026