PublicDateAtUSN: 2019-04-02 Candidate: CVE-2019-0217 PublicDate: 2019-04-08 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0217 https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2019-0217 https://ubuntu.com/security/notices/USN-3937-1 https://ubuntu.com/security/notices/USN-3937-2 Description: In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Simon Kappel Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.5 HIGH] Patches_apache2: upstream: https://github.com/apache/httpd/commit/44b3ddc560c490c60600998fa2bf59b142d08e05 upstream_apache2: needs-triage precise/esm_apache2: released (2.2.22-1ubuntu1.15) trusty_apache2: released (2.4.7-1ubuntu4.22) trusty/esm_apache2: released (2.4.7-1ubuntu4.22) xenial_apache2: released (2.4.18-2ubuntu3.10) esm-infra/xenial_apache2: released (2.4.18-2ubuntu3.10) bionic_apache2: released (2.4.29-1ubuntu4.6) cosmic_apache2: released (2.4.34-1ubuntu2.1) devel_apache2: released (2.4.38-2ubuntu2)