In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the apgetbasicauthpw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-3167.json"