CVE-2019-0220: Medium severity Apache HTTP Server vulnerability
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-73.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-54.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-9.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-21.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-41.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-24.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-10.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-4.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-73.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-54.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-9.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-21.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-41.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-24.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-10.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1c-4.jbcs.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-90.el7 - Upgrade
Upgrade
redhat/httpd24to a version that resolves this vulnerability.Fixed in 0:1.1-19.el6 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-15.el6 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-8.el6 - Upgrade
Upgrade
redhat/httpd24to a version that resolves this vulnerability.Fixed in 0:1.1-19.el7 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-15.el7 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-8.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.39 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1 - Compensating control
Update Apache HTTP Server 2.4.0–2.4.38 mitigations by adjusting directives that match the request URL path (e.g., LocationMatch and RewriteRule) to use regular expressions that account for duplicate multiple consecutive slashes ('/'), since Apache processing will implicitly collapse consecutive slashes but regex matches must handle them explicitly.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-0220?
The severity of CVE-2019-0220 is low with a CVSS score of 3.3.
What is the impact of CVE-2019-0220?
CVE-2019-0220 allows an attacker to bypass intended access restrictions and perform unauthorized actions.
How do I fix CVE-2019-0220?
To fix CVE-2019-0220, update your Apache HTTP Server to version 2.4.39 or apply the appropriate patch provided by RedHat.
Where can I find more information about CVE-2019-0220?
You can find more information about CVE-2019-0220 on the official Apache HTTP Server website, the Apache HTTP Server changelog, and the RedHat Bugzilla page.
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2019-0220.