CVE-2018-1312

Advisory lineage Upstream: 0 Downstream: 16
Modified
Published: 26 Mar 2018, 15:00
Last modified:16 Sept 2024, 19:14

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
7.28% LOW
7% probability +0.33%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Mar 2018, 15:00
Published
Vulnerability first disclosed
16 Sept 2024, 19:14
Last Modified
Vulnerability information updated

Description

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 7.28% Percentile: 92%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Systems

  • apache software foundationapache http server

    2.0.42 to 2.4.29

  • UnknownHTTP Server

    2.4.1 | 2.4.2 | 2.4.3 | 2.4.4 | 2.4.6 | 2.4.7 | 2.4.9 | 2.4.10 | 2.4.12 | 2.4.16 | 2.4.17 | 2.4.18 | 2.4.20 | 2.4.23 | 2.4.25 | 2.4.26 | 2.4.27 | 2.4.28 | 2.4.29

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 17.10 | 18.04

  • debiandebian_linux

    7.0 | 8.0 | 9.0

  • netappcloud_backup

    na

  • netappclustered_data_ontap

    na

  • netappstoragegrid

    na

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_eus

    7.6

  • redhatenterprise_linux_server

    7.0

  • redhatenterprise_linux_server_aus

    7.6

  • redhatenterprise_linux_server_tus

    7.6

  • redhatenterprise_linux_workstation

    7.0

  • redhatjboss_core_services

    1.0

References (29)