cbcvebase.
CVE-2019-0217
published 2019-04-08

CVE-2019-0217: In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid…

high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

Affected

23 ranges
VendorProductVersion rangeFixed in
apacheapache_http_server
apachehttp_server2.4.0 – 2.4.38
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.4.38-3 (bookworm)apache2 2.4.38-3 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
opensuseleap
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oraclehttp_server
oracleretail_xstore_point_of_service
oracleretail_xstore_point_of_service
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH