ZeroHour

CVE-2018-1312

CVSS 3.1
9.8 critical
EPSS
16%p97
Published
()
Modified
Description

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

Vendors
apachecanonicaldebiannetappredhat
Products
http server, ubuntu linux, debian linux, cloud backup, storagegrid, clustered data ontap, jboss core services, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.