CVE-2016-4979

The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.


We have discovered 659,136 live websites that are affected by CVE-2016-4979.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains659,136 live websites (26% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.20
Vulnerable Versions Count80 versions ( 66% of all versions)



Details

  • Published - Jul 6, 2016
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2016-4979
United States162,424 websites



Taiwan107,572 websites
Germany53,658 websites
Japan40,138 websites
France27,154 websites
Russia26,863 websites
Netherlands25,938 websites
Italy17,170 websites
Czech Republic16,830 websites
Korea, South14,652 websites

Website Distribution by TLD

Number of websites using CVE-2016-4979
.com299,798 websites
.de37,957 websites
.net26,589 websites
.org23,110 websites
.ru22,993 websites
.nl19,354 websites
.it14,044 websites
.cz13,802 websites
.info12,231 websites
.jp11,517 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-4979

Top websites that are affected by CVE-2016-4979. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
***.****.us United States*,***
******************.com United States*,***
*******.**.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
********.in India*,***
******.com Japan*,***
See full domain list

FAQ

A total of 659,136 websites have been identified as vulnerable to CVE-2016-4979, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2016-4979 vulnerability.
Apache versions up to and including 2.4.20 are vulnerable to CVE-2016-4979.

References