The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2005-10-13T04:00:00

Updated: 2024-08-07T22:53:30.042Z

Reserved: 2005-09-19T00:00:00

Link: CVE-2005-2963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-10-13T21:02:00.000

Modified: 2024-11-21T00:00:49.287

Link: CVE-2005-2963

cve-icon Redhat

No data.