CVE-2019-0211
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache HTTP Server Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 65% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-416
מוצרים מושפעים
apache: http server; fedoraproject: fedora; canonical: ubuntu linux; debian: debian linux; opensuse: leap; netapp: oncommand unified manager; redhat: jboss core services; redhat: openshift container platform; redhat: openshift container platform for power; redhat: software collections; redhat: enterprise linux; redhat: enterprise linux eus; redhat: enterprise linux for arm 64; redhat: enterprise linux for arm 64 eus; redhat: enterprise linux for ibm z systems
קישורים
- http://www.apache.org/dist/httpd/CHANGES_2.4.39 Broken LinkVendor Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html Vendor Advisory
- http://www.apache.org/dist/httpd/CHANGES_2.4.39 Broken LinkVendor Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html Vendor Advisory
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5… Mailing ListPatch
- https://seclists.org/bugtraq/2019/Apr/16 Mailing ListPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5… Mailing ListPatch