Lucene search

K
redhatcveRedhat.comRH:CVE-2019-0215
HistoryApr 02, 2019 - 10:50 a.m.

CVE-2019-0215

2019-04-0210:50:24
redhat.com
access.redhat.com
22

0.003 Low

EPSS

Percentile

67.8%

A flaw was found in Apache HTTP Server 2.4 (releases 2.4.37 and 2.4.38). A bug in mod_ssl, when using per-location client certificate verification with TLSv1.3, allowed a client supporting Post-Handshake Authentication to bypass configured access control restrictions. An attacker could perform various unauthorized actions after bypassing the restrictions. The highest threat from this vulnerability is to data confidentiality and integrity.