Lucene search

K
osvGoogleOSV:CVE-2019-0217
HistoryApr 08, 2019 - 9:29 p.m.

CVE-2019-0217

2019-04-0821:29:00
Google
osv.dev
5

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.8%

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

References