PT-2019-3931 · Apache+3 · Apache Http Server+3

Published

2019-01-23

·

Updated

2023-08-27

·

CVE-2019-0215

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.37 through 2.4.38
Description The issue is related to a flaw in the mod ssl component of the Apache HTTP Server, specifically concerning inadequate access control. This flaw can be exploited by a remote attacker to bypass configured access control restrictions when client certificate verification is used with TLSv1.3. The attack can be launched remotely.
Recommendations For versions 2.4.37 and 2.4.38, consider disabling the use of TLSv1.3 with client certificate verification until a patch is available. As a temporary workaround, restrict access to locations using per-location client certificate verification to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1580
BDU:2019-04409
CESA-2019_0980
CVE-2019-0215
DLA-3351-1
RHSA-2019:0980
RHSA-2019_0980

Affected Products

Alt Linux
Apache Http Server
Centos
Red Hat