Apache 2.4.20 X509 Authentication Bypass

Discussion in 'News Aggregator' started by Packet Storm, 6 Jul 2016.

  1. Packet Storm

    Packet Storm Guest

    Apache HTTPD WebServer versions 2.4.18 through 2.4.20 do not validate an X509 client certificate correctly when the experimental module for the HTTP/2 protocol is used to access a resource.

    Continue reading...
     

Share This Page

Loading...