CVE-2019-0217: Race Condition
A race condition was found in modauthdigest when the web server was running in a threaded MPM configuration. It could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Other sources
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in modauthdigest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-90.el7 - Upgrade
Upgrade
redhat/httpd24to a version that resolves this vulnerability.Fixed in 0:1.1-19.el6 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-15.el6 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-8.el6 - Upgrade
Upgrade
redhat/httpd24to a version that resolves this vulnerability.Fixed in 0:1.1-19.el7 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-15.el7 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-8.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.39 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Server (httpd)to a version that resolves this vulnerability.Fixed in 2.4.38 - Configuration
Use the prefork MPM instead of a threaded MPM configuration to mitigate the mod_auth_digest race condition (affects threaded server configuration).
Apache HTTP Server MPM MPM mode = prefork
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-0217?
CVE-2019-0217 is classified as a high severity vulnerability due to its potential to bypass authentication controls.
How do I fix CVE-2019-0217?
To mitigate CVE-2019-0217, upgrade Apache HTTP Server to version 2.4.39 or later.
Who is affected by CVE-2019-0217?
CVE-2019-0217 affects Apache HTTP Server versions 2.4.38 and earlier when run in a threaded MPM configuration.
What kind of vulnerability is CVE-2019-0217?
CVE-2019-0217 is a race condition vulnerability in mod_auth_digest, enabling authentication bypass.
What products are related to CVE-2019-0217?
Apache HTTP Server, Red Hat products including jbcs-httpd24-apr and various utilities are related to CVE-2019-0217.