CVE-2014-8109

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.


We have discovered 303,878 live websites that are affected by CVE-2014-8109.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains303,878 live websites (12% of Apache install base)
Vulnerable Versions
  • from 2.3 through 2.3
  • from 2.4 through 2.4.10
Vulnerable Versions Count10 versions ( 8.13% of all versions)



Details

  • Published - Dec 29, 2014
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2014-8109
United States103,905 websites



Germany21,551 websites
Singapore18,213 websites
Japan17,675 websites
France15,821 websites
Netherlands15,318 websites
Russia10,983 websites
Italy8,148 websites
Czech Republic7,610 websites
Korea, South5,958 websites

Website Distribution by TLD

Number of websites using CVE-2014-8109
.com134,212 websites
.de13,224 websites
.net12,170 websites
.org11,876 websites
.nl11,358 websites
.ru9,249 websites
.it6,790 websites
.cz6,198 websites
.fr5,103 websites
.jp4,368 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2014-8109

Top websites that are affected by CVE-2014-8109. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com United States*,***
****.com United States*,***
********.com United States*,***
*.******.***.***.br Brazil*,***
*************.com GB*,***
*.*****.***.***.br Brazil*,***
******.com France*,***
**************.**.uk GB*,***
****.**.com United States*,***
****.org United States*,***
See full domain list

FAQ

A total of 303,878 websites have been identified as vulnerable to CVE-2014-8109, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2014-8109 vulnerability.
Apache versions up to and including 2.4.10 are vulnerable to CVE-2014-8109.

References