In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
http://www.openwall.com/lists/oss-security/2018/03/24/7
http://www.securityfocus.com/bid/103524
http://www.securitytracker.com/id/1040571
https://access.redhat.com/errata/RHSA-2018:3558
https://access.redhat.com/errata/RHSA-2019:0366
https://access.redhat.com/errata/RHSA-2019:0367
https://access.redhat.com/errata/RHSA-2019:1898
https://httpd.apache.org/security/vulnerabilities_24.html
https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E
https://lists.debian.org/debian-lts-announce/2018/05/msg00020.html
https://security.netapp.com/advisory/ntap-20180601-0004/
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us
https://usn.ubuntu.com/3627-1/
https://usn.ubuntu.com/3627-2/
Source: MITRE
Published: 2018-03-26
Updated: 2019-07-29
Type: CWE-287
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 3.9
Severity: CRITICAL
OR
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* versions from 2.2.0 to 2.2.34 (inclusive)
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* versions from 2.4.0 to 2.4.29 (inclusive)
OR
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
OR
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
OR
cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*
OR
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
129905 | NewStart CGSL CORE 5.04 / MAIN 5.04 : httpd Vulnerability (NS-SA-2019-0182) | Nessus | NewStart CGSL Local Security Checks | medium |
128695 | NewStart CGSL CORE 5.05 / MAIN 5.05 : httpd Vulnerability (NS-SA-2019-0172) | Nessus | NewStart CGSL Local Security Checks | medium |
127725 | Scientific Linux Security Update : httpd on SL7.x x86_64 (20190729) | Nessus | Scientific Linux Local Security Checks | medium |
127625 | RHEL 7 : httpd (RHSA-2019:1898) | Nessus | Red Hat Local Security Checks | medium |
127608 | Oracle Linux 7 : httpd (ELSA-2019-1898) | Nessus | Oracle Linux Local Security Checks | medium |
127474 | CentOS 7 : httpd (CESA-2019:1898) | Nessus | CentOS Local Security Checks | medium |
124922 | EulerOS Virtualization 3.0.1.0 : httpd (EulerOS-SA-2019-1419) | Nessus | Huawei Local Security Checks | high |
122292 | RHEL 6 / 7 : Red Hat JBoss Core Services Apache HTTP Server 2.4.29 (RHSA-2019:0367) | Nessus | Red Hat Local Security Checks | medium |
122060 | Apache 2.4.x < 2.4.33 Multiple Vulnerabilities | Nessus | Web Servers | medium |
121275 | EulerOS Virtualization 2.5.1 : httpd (EulerOS-SA-2019-1015) | Nessus | Huawei Local Security Checks | medium |
98914 | Apache 2.4.x < 2.4.33 Multiple Vulnerabilities | Web Application Scanning | Component Vulnerability | medium |
120484 | Fedora 28 : httpd (2018-6744ca470d) | Nessus | Fedora Local Security Checks | medium |
118251 | SUSE SLES12 Security Update : apache2 (SUSE-SU-2018:1161-2) | Nessus | SuSE Local Security Checks | medium |
110877 | EulerOS 2.0 SP3 : httpd (EulerOS-SA-2018-1213) | Nessus | Huawei Local Security Checks | medium |
110250 | Debian DLA-1389-1 : apache2 security update | Nessus | Debian Local Security Checks | medium |
110156 | EulerOS 2.0 SP2 : httpd (EulerOS-SA-2018-1152) | Nessus | Huawei Local Security Checks | medium |
110155 | EulerOS 2.0 SP1 : httpd (EulerOS-SA-2018-1151) | Nessus | Huawei Local Security Checks | medium |
109745 | Fedora 26 : httpd (2018-e6d9251471) | Nessus | Fedora Local Security Checks | medium |
109664 | openSUSE Security Update : apache2 (openSUSE-2018-438) | Nessus | SuSE Local Security Checks | medium |
109598 | SUSE SLES12 Security Update : apache2 (SUSE-SU-2018:1161-1) | Nessus | SuSE Local Security Checks | medium |
109555 | Amazon Linux AMI : httpd24 (ALAS-2018-1004) | Nessus | Amazon Linux Local Security Checks | medium |
109466 | Ubuntu 18.04 LTS : Apache HTTP Server vulnerabilities (USN-3627-2) | Nessus | Ubuntu Local Security Checks | medium |
109359 | SUSE SLES11 Security Update : apache2 (SUSE-SU-2018:1079-1) | Nessus | SuSE Local Security Checks | medium |
109199 | Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : Apache HTTP Server vulnerabilities (USN-3627-1) | Nessus | Ubuntu Local Security Checks | medium |
108945 | SUSE SLES12 Security Update : apache2 (SUSE-SU-2018:0901-1) | Nessus | SuSE Local Security Checks | medium |
108876 | SUSE SLES12 Security Update : apache2 (SUSE-SU-2018:0879-1) | Nessus | SuSE Local Security Checks | medium |
108856 | Fedora 27 : httpd (2018-375e3244b6) | Nessus | Fedora Local Security Checks | medium |
108816 | Debian DSA-4164-1 : apache2 - security update | Nessus | Debian Local Security Checks | medium |
108758 | Apache 2.4.x < 2.4.33 Multiple Vulnerabilities (deprecated) | Nessus | Web Servers | medium |
108626 | FreeBSD : apache -- multiple vulnerabilities (f38187e7-2f6e-11e8-8f07-b499baebfeaf) | Nessus | FreeBSD Local Security Checks | medium |