The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.
We have discovered 659,136 live websites that are affected by CVE-2016-4979.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 659,136 live websites (26% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 80 versions ( 66% of all versions) |
| 162,424 websites | |
| 107,572 websites | |
| 53,658 websites | |
| 40,138 websites | |
| 27,154 websites | |
| 26,863 websites | |
| 25,938 websites | |
| 17,170 websites | |
| 16,830 websites | |
| 14,652 websites |
| .com | 299,798 websites |
| .de | 37,957 websites |
| .net | 26,589 websites |
| .org | 23,110 websites |
| .ru | 22,993 websites |
| .nl | 19,354 websites |
| .it | 14,044 websites |
| .cz | 13,802 websites |
| .info | 12,231 websites |
| .jp | 11,517 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| ***.****.us | *,*** | ||
| ******************.com | *,*** | ||
| *******.**.com | *,*** | ||
| *********.******.net | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| ****.**.pl | *,*** | ||
| ********.in | *,*** | ||
| ******.com | *,*** |