← All CVEs

CVE-2018-17199

high · 7.5

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

7.5
CVSS
20.2%
EPSS (exploit prob.)
97th
EPSS percentile
2019-01-30
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-384

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, <= 2.4.37
debiandebian_linux8.0
debiandebian_linux9.0
netappsantricity_cloud_connectorall versions
netappstorage_automation_storeall versions
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux18.10
oracleenterprise_manager_ops_center12.3.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-17199