Vulnerability Description
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 2.4.37 |
| Fedoraproject | Fedora | 29 |
References
- http://www.openwall.com/lists/oss-security/2019/04/02/4Mailing ListMitigationThird Party Advisory
- http://www.securityfocus.com/bid/107667Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:0980
- https://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- https://lists.apache.org/thread.html/117bc3f09847ebf020b1bb70301ebcc105ddc446856
- https://lists.apache.org/thread.html/2d6bd429a0ba9af1580da896575cfca6e42bb05e753
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cd
- https://lists.apache.org/thread.html/5b1e7d66c5adf286f14f6cc0f857b6fca107444f68a
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e10
- https://lists.apache.org/thread.html/bc1a6d4137798565ab02e60079b6788442147f4efeb
- https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f60
- https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f8
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa
FAQ
What is CVE-2019-0215?
CVE-2019-0215 is a vulnerability with a CVSS score of 7.5 (HIGH). In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restric...
How severe is CVE-2019-0215?
CVE-2019-0215 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0215?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Fedoraproject Fedora.