Access Control Bypass in Apache HTTP Server with mod_ssl
CVE-2025-23048
Key Information:
- Vendor
Apache
- Status
- Vendor
- CVE Published:
- 10 July 2025
Badges
What is CVE-2025-23048?
In certain configurations of mod_ssl within Apache HTTP Server versions 2.4.35 to 2.4.63, a vulnerability may allow an authenticated client, trusted by one virtual host, to gain unauthorized access to another virtual host. This occurs when SSLStrictSNIVHostCheck is not enabled across these virtual hosts configured with different sets of trusted client certificates. Such settings pose a risk particularly in environments utilizing TLS 1.3 session resumption, suggesting a need for careful setup to ensure proper access controls are sustained.
Affected Version(s)
Apache HTTP Server 2.4.35 <= 2.4.63
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved