CVE-2017-12171: Apache HTTP Server

Medium severity, CVSS 6.5. EPSS: 8.1% chance of exploitation in the next 30 days.

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.

Affected products

  • Apache HTTP Server: version 2.2.15-60 only
  • Red Hat Enterprise Linux: version 6.9 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2018-07-26. Last modified 2026-06-17.