cbcvebase.
CVE-2018-1312
published 2018-03-26

CVE-2018-1312: In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
15.88%
96.5th percentile
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttpd
apache_software_foundationapache_http_server
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability affects Apache httpd mod_auth_digest module; detect exploitation attempts by monitoring for replayed HTTP Digest authentication requests across clustered servers — the nonce value in the Authorization header will be reused across different servers in the cluster.
  • Focus detection on the mod_auth_digest module specifically; the weak nonce generation is the root cause — monitor for identical nonce values appearing in Digest authentication headers across multiple servers.
  • Affected Apache httpd versions for scoping detection/asset inventory: 2.4.1 through 2.4.29 (and 2.2.0 through 2.2.x); patched in 2.4.33.
  • ·The vulnerability is only exploitable when 'AuthType Digest' is explicitly configured; the default Apache httpd configuration does NOT enable mod_auth_digest, so default installs are not affected.
  • ·The attack requires a cluster of servers sharing a common Digest authentication configuration; single-server deployments are not susceptible to cross-server replay.
  • ·Red Hat upstream discourages use of mod_auth_digest entirely due to inherent security weaknesses and recommends mod_ssl instead.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_apache9.8LOW
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.