← All CVEs

CVE-2019-0217

high · 7.5

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

7.5
CVSS
17.4%
EPSS (exploit prob.)
97th
EPSS percentile
2019-04-08
Published

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-362

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, <= 2.4.38
debiandebian_linux8.0
debiandebian_linux9.0
fedoraprojectfedora28
fedoraprojectfedora29
fedoraprojectfedora30
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux18.10
redhatenterprise_linuxall versions
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_workstation7.0
opensuseleap15.0
opensuseleap42.3
netapponcommand_unified_managerall versions
netappclustered_data_ontapall versions
oracleenterprise_manager_ops_center12.3.3
oracleenterprise_manager_ops_center12.4.0
oraclehttp_server12.2.1.3.0
oracleretail_xstore_point_of_service7.0
oracleretail_xstore_point_of_service7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-0217