Description

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.

INFO

Published Date :

2025-07-10T16:56:53.545Z

Last Modified :

2026-02-26T17:50:47.700Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2025-23048 vulnerability.

Vendors Products
Apache
  • Http Server
Apache Software Foundation
  • Apache Http Server

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact