PT-2019-3931 · Apache+3 · Apache Http Server+3
Published
2019-01-23
·
Updated
2023-08-27
·
CVE-2019-0215
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.37 through 2.4.38
Description
The issue is related to a flaw in the mod ssl component of the Apache HTTP Server, specifically concerning inadequate access control. This flaw can be exploited by a remote attacker to bypass configured access control restrictions when client certificate verification is used with TLSv1.3. The attack can be launched remotely.
Recommendations
For versions 2.4.37 and 2.4.38, consider disabling the use of TLSv1.3 with client certificate verification until a patch is available.
As a temporary workaround, restrict access to locations using per-location client certificate verification to minimize the risk of exploitation.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Centos
Red Hat