ZeroHour

CVE-2018-17199

CVSS 3.0
7.5 high
EPSS
21%p97
Published
()
Modified
Description

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

Vendors
apachedebiannetappcanonicaloracle
Products
http server, debian linux, santricity cloud connector, storage automation store, ubuntu linux, enterprise manager ops center
Weakness
CWE-384
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.