Candidate: CVE-2019-0215 PublicDate: 2019-04-08 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0215 https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2019-0215 Description: In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions. Ubuntu-Description: Notes: mdeslaur> 2.4.37 and 2.4.38 only Bugs: Priority: medium Discovered-by: Michael Kaufmann Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.5 HIGH] Patches_apache2: upstream: https://github.com/apache/httpd/commit/84edf5f49db23ced03259812bbf9426685f7d82a upstream_apache2: needs-triage precise/esm_apache2: not-affected trusty_apache2: not-affected trusty/esm_apache2: not-affected xenial_apache2: not-affected esm-infra/xenial_apache2: not-affected bionic_apache2: not-affected cosmic_apache2: not-affected (2.4.34-1ubuntu2) devel_apache2: released (2.4.38-2ubuntu2)