ZeroHour

CVE-2019-0217

CVSS 3.1
7.5 high
EPSS
17%p97
Published
()
Modified
Description

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

Vendors
apachedebianfedoraprojectcanonicalredhatopensusenetapporacle
Products
http server, debian linux, fedora, ubuntu linux, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation, leap, oncommand unified manager, clustered data ontap, enterprise manager ops center
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news