A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-3747
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12171
https://access.redhat.com/errata/RHSA-2017:2972