Lucene search

K
httpdApache Team FoundationHTTPD:60420623F2A716909480F87DB74EE9D7
HistoryOct 08, 2018 - 12:00 a.m.

Apache Httpd < 2.4.38 : mod_session_cookie does not respect expiry time

2018-10-0800:00:00
Apache Team Foundation
httpd.apache.org
82

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.002

Percentile

56.6%

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

Affected configurations

Vulners
Node
apacheapache_httpdMatch2.4.37
OR
apacheapache_httpdMatch2.4.35
OR
apacheapache_httpdMatch2.4.34
OR
apacheapache_httpdMatch2.4.33
OR
apacheapache_httpdMatch2.4.30
OR
apacheapache_httpdMatch2.4.29
OR
apacheapache_httpdMatch2.4.28
OR
apacheapache_httpdMatch2.4.27
OR
apacheapache_httpdMatch2.4.26
OR
apacheapache_httpdMatch2.4.25
OR
apacheapache_httpdMatch2.4.23
OR
apacheapache_httpdMatch2.4.20
OR
apacheapache_httpdMatch2.4.18
OR
apacheapache_httpdMatch2.4.17
OR
apacheapache_httpdMatch2.4.16
OR
apacheapache_httpdMatch2.4.12
OR
apacheapache_httpdMatch2.4.10
OR
apacheapache_httpdMatch2.4.9
OR
apacheapache_httpdMatch2.4.7
OR
apacheapache_httpdMatch2.4.6
OR
apacheapache_httpdMatch2.4.4
OR
apacheapache_httpdMatch2.4.3
OR
apacheapache_httpdMatch2.4.2
OR
apacheapache_httpdMatch2.4.1
OR
apacheapache_httpdMatch2.4.0
VendorProductVersionCPE
apacheapache_httpd2.4.37cpe:2.3:a:apache:apache_httpd:2.4.37:*:*:*:*:*:*:*
apacheapache_httpd2.4.35cpe:2.3:a:apache:apache_httpd:2.4.35:*:*:*:*:*:*:*
apacheapache_httpd2.4.34cpe:2.3:a:apache:apache_httpd:2.4.34:*:*:*:*:*:*:*
apacheapache_httpd2.4.33cpe:2.3:a:apache:apache_httpd:2.4.33:*:*:*:*:*:*:*
apacheapache_httpd2.4.30cpe:2.3:a:apache:apache_httpd:2.4.30:*:*:*:*:*:*:*
apacheapache_httpd2.4.29cpe:2.3:a:apache:apache_httpd:2.4.29:*:*:*:*:*:*:*
apacheapache_httpd2.4.28cpe:2.3:a:apache:apache_httpd:2.4.28:*:*:*:*:*:*:*
apacheapache_httpd2.4.27cpe:2.3:a:apache:apache_httpd:2.4.27:*:*:*:*:*:*:*
apacheapache_httpd2.4.26cpe:2.3:a:apache:apache_httpd:2.4.26:*:*:*:*:*:*:*
apacheapache_httpd2.4.25cpe:2.3:a:apache:apache_httpd:2.4.25:*:*:*:*:*:*:*
Rows per page:
1-10 of 251

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.002

Percentile

56.6%