CVE-2015-3185 is a vulnerability in Apache HTTP Server 2.4.x before 2.4.14, affecting Apache, Apple, and Canonical products. It allows remote attackers to bypass access restrictions by exploiting a flaw in the ap_some_auth_required function, which incorrectly handles Require directives in conjunction with modules relying on the 2.2 API. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, requiring no authentication, and potentially leading to partial integrity impact. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low attention to this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* | ||
2.4.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.0:*:*:*:*:*:*:* | ||
2.4.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: ap_some_auth_required() does not properly indicate authenticated request in 2.4
Jul 15, 2015Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project