Use of the ap_get_basic_auth_pw() in Apache httpd by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed. References: https://lists.apache.org/thread.html/8409e41a8f7dd9ded37141c38df001be930115428c3d64f70bbdb8b4@%3Cdev.httpd.apache.org%3E External References: https://httpd.apache.org/security/vulnerabilities_24.html https://httpd.apache.org/security/vulnerabilities_22.html
Created httpd tracking bugs for this issue: Affects: fedora-all [bug 1463208]
Upstream commit: 2.4: https://github.com/apache/httpd/commit/78f0f0b6585f13ec1175c7020ee01cd0237fc1ba 2.2: https://github.com/apache/httpd/commit/7103baa2e70e37eeaf7847abaa6f3567ef2cdf73
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:2478 https://access.redhat.com/errata/RHSA-2017:2478
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:2479 https://access.redhat.com/errata/RHSA-2017:2479
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Via RHSA-2017:2483 https://access.redhat.com/errata/RHSA-2017:2483
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.2 Extended Update Support Via RHSA-2017:3193 https://access.redhat.com/errata/RHSA-2017:3193
This issue has been addressed in the following products: Red Hat Enterprise Linux 6.7 Extended Update Support Via RHSA-2017:3195 https://access.redhat.com/errata/RHSA-2017:3195
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.3 Extended Update Support Via RHSA-2017:3194 https://access.redhat.com/errata/RHSA-2017:3194
This issue has been addressed in the following products: Red Hat JBoss Core Services Via RHSA-2017:3475 https://access.redhat.com/errata/RHSA-2017:3475
This issue has been addressed in the following products: JBoss Core Services on RHEL 7 Via RHSA-2017:3476 https://access.redhat.com/errata/RHSA-2017:3476
This issue has been addressed in the following products: JBoss Core Services on RHEL 6 Via RHSA-2017:3477 https://access.redhat.com/errata/RHSA-2017:3477