CVE-2018-1312
—CVSS 3.1
9.8 critical
EPSS
16%p97
Published
()
Modified
Description
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
- Vendors
- apachecanonicaldebiannetappredhat
- Products
- http server, ubuntu linux, debian linux, cloud backup, storagegrid, clustered data ontap, jboss core services, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.