Description
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4589)
WordPress Other Vulnerability (CVE-2006-6016)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0714)
math.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-1001002)
WordPress Plugin Digital Publications by Supsystic Multiple Vulnerabilities (1.6.9)