« Volver al listado

CVE-2013-4566

Estado: ModificadaMedia (4)—

mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4566",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-12-12T18:55:10.947",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-12/msg00118.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-1779.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1016832",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-12/msg00118.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-1779.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1016832",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions."
    },
    {
      "lang": "es",
      "value": "mod_nss 1.0.8 y anteriores versiones, cuando se establece NSSVerifyClient en none para el contexto del server/vhost, no aplica la opción de NSSVerifyClient en el contexto de directorio, lo que permite a atacantes remotos evadir restricciones de acceso intencionadas."
    }
  ],
  "lastModified": "2026-06-16T23:57:27.890",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D938A66B-3BE0-46EA-BD41-91A21651E298",
              "versionEndIncluding": "1.0.8"
            },
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85B16378-B282-44E2-8716-C76634FAC7D1"
            },
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53FC2306-99BB-4F92-AA60-27DFC777947E"
            },
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "574AAC71-ADB7-4CFB-8278-BF305AEF67D3"
            },
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20747B2B-A9FD-45A6-9E83-7FF4B3619E9C"
            },
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:1.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "451CA213-63CF-4EC7-866D-6219CF8CB218"
            },
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:1.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94CE91B7-D935-4D51-9207-D47CE1C62ACB"
            },
            {
              "criteria": "cpe:2.3:a:mod_nss_project:mod_nss:1.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E58BD70-C4E3-4899-AE0F-71ECC23E6C67"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA9B3CC0-DF1C-4A86-B2A3-A9D428A5A6E6"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F6AB192-9D7D-4A9A-8995-E53A9DE9EAFC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}