← לוח פגיעויות

CVE-2019-0211

גבוהה 7.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Apache HTTP Server Privilege Escalation Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

מדדים

CVSS 3.1
7.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
65% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-416

מוצרים מושפעים

apache: http server; fedoraproject: fedora; canonical: ubuntu linux; debian: debian linux; opensuse: leap; netapp: oncommand unified manager; redhat: jboss core services; redhat: openshift container platform; redhat: openshift container platform for power; redhat: software collections; redhat: enterprise linux; redhat: enterprise linux eus; redhat: enterprise linux for arm 64; redhat: enterprise linux for arm 64 eus; redhat: enterprise linux for ibm z systems

קישורים