CVE-2018-17199

Modified
Published: 30 Jan 2019, 22:00
Last modified:16 Sept 2024, 19:35

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.5 HIGH
v3.0 (nvd)
EPSS Score
10.46% MEDIUM
10% probability +0.16%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jan 2019, 22:00
Published
Vulnerability first disclosed
16 Sept 2024, 19:35
Last Modified
Vulnerability information updated

Description

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS Metrics

  • v3.0HIGHScore: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 10.46% Percentile: 93%

Techniques & Countermeasures

  • CWE-384Session Fixation

    Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Systems

  • apache software foundationapache http server

    Apache HTTP Server 2.4.0 to 2.4.37

  • UnknownHTTP Server

    ≥ 2.4.0, ≤ 2.4.37

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 18.10

  • debiandebian_linux

    8.0 | 9.0

  • netappsantricity_cloud_connector

    na

  • netappstorage_automation_store

    na

  • oracleenterprise_manager_ops_center

    12.3.3

References (28)