mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.
We have discovered 303,878 live websites that are affected by CVE-2014-8109.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 303,878 live websites (12% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 10 versions ( 8.13% of all versions) |
| 103,905 websites | |
| 21,551 websites | |
| 18,213 websites | |
| 17,675 websites | |
| 15,821 websites | |
| 15,318 websites | |
| 10,983 websites | |
| 8,148 websites | |
| 7,610 websites | |
| 5,958 websites |
| .com | 134,212 websites |
| .de | 13,224 websites |
| .net | 12,170 websites |
| .org | 11,876 websites |
| .nl | 11,358 websites |
| .ru | 9,249 websites |
| .it | 6,790 websites |
| .cz | 6,198 websites |
| .fr | 5,103 websites |
| .jp | 4,368 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******************.com | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| *.******.***.***.br | *,*** | ||
| *************.com | *,*** | ||
| *.*****.***.***.br | *,*** | ||
| ******.com | *,*** | ||
| **************.**.uk | *,*** | ||
| ****.**.com | *,*** | ||
| ****.org | *,*** |