Security Advisory

CVE-2013-4566

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2013-12-12 18:00:00
Last updated 2024-08-06 16:45:15
Assigner redhat
State PUBLISHED

Description

mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.