oss-sec mailing list archives

CVE Request: "LuaAuthzProvider" in Apache HTTP Server mixes up arguments


From: Eric Covener <covener () gmail com>
Date: Fri, 28 Nov 2014 09:44:32 -0500

https://issues.apache.org/bugzilla/show_bug.cgi?id=57204

LuaAuthzProvider in Apache HTTP Server 2.4.3 and later allows users to
supply their own Lua scripts to perform authorization.  If the same
script is specified in httpd.conf  multiple times, with different
(free-form) arguments, only the last specified argument is used for
all invocations of the script.


Current thread: