CVE-2019-0190
published 2019-01-30CVE-2019-0190: A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a…
PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
59.94%
99.0th percentile
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | — | — |
| debian | apache2 | < apache2 2.4.38-1 (bookworm) | apache2 2.4.38-1 (bookworm) |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | hospitality_guest_access | — | — |
| oracle | hospitality_guest_access | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target: Apache HTTP Server 2.4.37 combined with OpenSSL 1.1.1 or later — the infinite loop DoS via mod_ssl client renegotiation is only triggerable on this exact version combination ↗
- →Attack vector: client-initiated TLS renegotiation over HTTPS — monitor for abnormal or repeated TLS renegotiation handshakes from a single remote client against mod_ssl endpoints ↗
- →Detection signal: Apache httpd worker/process entering an infinite loop (CPU spin, unresponsive worker) following a client-initiated renegotiation — correlate with process-level monitoring of httpd workers ↗
- →Protocol scope: exploit is delivered exclusively over HTTPS — focus TLS inspection and anomaly detection on port 443 (or any SSL/TLS-enabled listener) on Apache 2.4.37 hosts ↗
- ·Vulnerability is version-locked: only Apache HTTP Server 2.4.37 is affected; all earlier and later versions (including the fixed 2.4.38) are not vulnerable — version fingerprinting is essential before triaging alerts ↗
- ·OpenSSL version is a hard prerequisite: the bug only manifests when OpenSSL 1.1.1 or later is in use; systems running older OpenSSL with Apache 2.4.37 are not exploitable ↗
- ·All Red Hat Enterprise Linux (5–8), JBoss, and Red Hat Software Collections packages are listed as Not Affected — do not prioritize patching effort on RHEL-based deployments of httpd ↗
- ·Fix is available in Apache 2.4.38; Debian resolved the issue in package version 2.4.38-1 across all tracked suites ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Essbase Risk Matrix: Infrastructure (OpenSSL) — CVE-2019-0190
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2019-0190 [HIGH] Oracle Oracle Essbase Risk Matrix: Infrastructure (OpenSSL) — CVE-2019-0190
Oracle Oracle Essbase Risk Matrix: Infrastructure (OpenSSL) vulnerability
CVE: CVE-2019-0190
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1
vendor_redhat·2019-01-22·CVSS 7.5
CVE-2019-0190 [HIGH] CWE-835 httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1
httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
A flaw was found in the way mod_ssl handled client renegotiations. A remote attacker could send a malicious request to cause mod_ssl to enter an infinite loop resulting in a denial of service.
Package: httpd (CloudForms Management Engine 5) - Not affected
Package: httpd (Red Hat Enterprise Linux 5) - Not affected
Pac
Debian
CVE-2019-0190: apache2 - A bug exists in the way mod_ssl handled client renegotiations. A remote attacker...
vendor_debian·2019·CVSS 7.5
CVE-2019-0190 [HIGH] CVE-2019-0190: apache2 - A bug exists in the way mod_ssl handled client renegotiations. A remote attacker...
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
Scope: local
bookworm: resolved (fixed in 2.4.38-1)
bullseye: resolved (fixed in 2.4.38-1)
forky: resolved (fixed in 2.4.38-1)
sid: resolved (fixed in 2.4.38-1)
trixie: resolved (fixed in 2.4.38-1)
Apache
Apache httpd: CVE-2019-0190
vendor_apache·CVSS 7.5
CVE-2019-0190 [HIGH] Apache httpd: CVE-2019-0190
Apache httpd: CVE-2019-0190
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts. Acknowledgements: The issue was discovered through user bug reports. Reported to security team 2019-01-01 Issue public 2019-01-22 Update 2.4.38 released 2019-02-28 Affects 2.4.37
Severity: high
Affected versions: 2.4.37
GHSA
GHSA-m3q7-x278-m229: A bug exists in the way mod_ssl handled client renegotiations
ghsa_unreviewed·2022-05-13
CVE-2019-0190 [HIGH] GHSA-m3q7-x278-m229: A bug exists in the way mod_ssl handled client renegotiations
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
OSV
CVE-2019-0190: A bug exists in the way mod_ssl handled client renegotiations
osv·2019-01-30·CVSS 7.5
CVE-2019-0190 [HIGH] CVE-2019-0190: A bug exists in the way mod_ssl handled client renegotiations
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
VulnCheck
Apache HTTP Server mod_ssl when used with OpenSSL Vulnerability
vulncheck·2019·CVSS 7.5
CVE-2019-0190 [HIGH] Apache HTTP Server mod_ssl when used with OpenSSL Vulnerability
Apache HTTP Server mod_ssl when used with OpenSSL Vulnerability
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
Affected: Apache HTTP Server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.trendmicro.com/en_us/research/22/b/recent-cyberattacks-open-source-web-servers.html
No detection rules found.
No public exploits indexed.
Trendmicro
Cyberangriffe auf Open Source-Webserver
blogs_trendmicro·2022-03-03·CVSS 9.8
[CRITICAL] Cyberangriffe auf Open Source-Webserver
APT und gezielte Angriffe
## Cyberangriffe auf Open Source-Webserver
Cyberangriffe auf Open-Source-Webserver wie Apache HTTP Server haben rapide zugenommen. Angriffe wie die Ausführung von Remote-Code, die Umgehung von Zugriffskontrollen, Denial-of-Service oder Cyberjacking dienen dem Mining von Kryptowährungen.
By: Jon Clay Mar 03, 2022 Read time: ( words)
Save to Folio
Originalartikel von Jon Clay, VP, Threat Intelligence
Cyberangriffe auf Open-Source-Webserver wie Apache HTTP Server haben rapide zugenommen. Böswillige Akteure setzen dabei auf Angriffe wie Remote Code Execution (RCE), Umgehung der Zugriffskontrolle, Denial of Service (DoS) oder sogar Cyberjacking, um auf den Servern der Opfer Kryptowährungen zu schürfen. Um Unternehmen vor bösartigen Aktivitäten zu schützen, bedarf
Trendmicro
Recent Cyberattacks Increasingly Target Open-source Web Servers
blogs_trendmicro·2022-02-22·CVSS 9.8
CVE-2021-44228 [CRITICAL] Recent Cyberattacks Increasingly Target Open-source Web Servers
APT & Targeted Attacks
# Recent Cyberattacks Target Open-source Web Servers
Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution, access control bypass, denial of service, or even cyberjacking the victim servers to mine cryptocurrencies.
By: Jon Clay
2022/02/22
Read time: ( words)
Save to Folio
As organizations reeled from the Log4Shell vulnerability (CVE-2021-44228), cyberattacks aiming at open-source web servers, like Apache HTTP Server, were rapidly rising. Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution (RCE), access control bypass, denial of service (DoS), or even cyberjacking the victim servers to mine cryptocurrencies.
To protect enterprises against m
Bugzilla
CVE-2019-0190 httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1 [fedora-29]
bugzilla·2019-01-22·CVSS 7.5
CVE-2019-0190 [HIGH] CVE-2019-0190 httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1 [fedora-29]
CVE-2019-0190 httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1 [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discu
Bugzilla
CVE-2019-0190 httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1
bugzilla·2019-01-22·CVSS 7.5
CVE-2019-0190 [HIGH] CVE-2019-0190 httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1
CVE-2019-0190 httpd: mod_ssl: infinite loop triggered by client-initiated renegotiation when using OpenSSL 1.1.1
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.
References:
https://seclists.org/oss-sec/2019/q1/82
https://httpd.apache.org/security/vulnerabilities_24.html
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-29 [bug 1668489]
---
Upstream bug and commit:
https://bz.apache.org/bugzilla/show_bug.cgi?id=63052
https://svn.apache.
http://www.securityfocus.com/bid/106743https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.gentoo.org/glsa/201903-21https://security.netapp.com/advisory/ntap-20190125-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.securityfocus.com/bid/106743https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://security.gentoo.org/glsa/201903-21https://security.netapp.com/advisory/ntap-20190125-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2019-01-30
Published
Exploited in the wild