← All CVEs

CVE-2005-2700

high · 10

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.

10
CVSS
30.6%
EPSS (exploit prob.)
98th
EPSS percentile
2005-09-06
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
apachehttp_server>= 2.0.35, < 2.0.55
debiandebian_linux3.0
debiandebian_linux3.1
canonicalubuntu_linux4.10
canonicalubuntu_linux5.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-2700