CVE-2019-0220

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

References

https://www.debian.org/security/2019/dsa-4422

https://usn.ubuntu.com/3937-1/

https://support.f5.com/csp/article/K44591505

https://seclists.org/bugtraq/2019/Apr/5

https://lists.fedoraproject.org/archives/list/[email protected]/message/WETXNQWNQLWHV6XNW6YTO5UGDTIWAQGT/

https://lists.fedoraproject.org/archives/list/[email protected]/message/EZRMTEIGZKYFNGIDOTXN3GNEJTLVCYU7/

https://lists.fedoraproject.org/archives/list/[email protected]/message/ALIR5S3O7NRHEGFMIDMUSYQIZOE4TJJN/

https://lists.debian.org/debian-lts-announce/2019/04/msg00008.html

https://httpd.apache.org/security/vulnerabilities_24.html

http://www.securityfocus.com/bid/107670

http://www.openwall.com/lists/oss-security/2019/04/02/6

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00084.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00061.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00051.html

https://security.netapp.com/advisory/ntap-20190625-0007/

https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

https://access.redhat.com/errata/RHSA-2019:2343

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03950en_us

https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

https://access.redhat.com/errata/RHSA-2019:3436

https://access.redhat.com/errata/RHSA-2019:4126

https://access.redhat.com/errata/RHSA-2020:0250

https://access.redhat.com/errata/RHSA-2020:0251

https://lists.apache.org/thread.html/[email protected]%3Cbugs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://www.oracle.com/security-alerts/cpuapr2020.html

https://www.oracle.com/security-alerts/cpujul2020.html

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

Details

Source: MITRE

Published: 2019-06-11

Updated: 2021-06-06

Type: CWE-706

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM

Tenable Plugins

View all (36 total)

IDNameProductFamilySeverity
145654CentOS 8 : httpd:2.4 (CESA-2019:3436)NessusCentOS Local Security Checks
high
144774IBM HTTP Server 7.0.0.0 <= 7.0.0.45 / 8.0.0.0 <= 8.0.0.15 / 8.5.0.0 < 8.5.5.16 / 9.0.0.0 < 9.0.5.0 Multiple Vulnerabilities (880413)NessusWeb Servers
high
144232Virtuozzo 7 : httpd / httpd-devel / httpd-manual / httpd-tools / etc (VZLSA-2019-2343)NessusVirtuozzo Local Security Checks
high
137492EulerOS 2.0 SP2 : httpd (EulerOS-SA-2020-1650)NessusHuawei Local Security Checks
medium
135617EulerOS Virtualization 3.0.2.2 : httpd (EulerOS-SA-2020-1455)NessusHuawei Local Security Checks
medium
134539EulerOS Virtualization for ARM 64 3.0.2.0 : httpd (EulerOS-SA-2020-1250)NessusHuawei Local Security Checks
medium
133333RHEL 6 : Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP1 Security Update (Low) (RHSA-2020:0250)NessusRed Hat Local Security Checks
medium
132454NewStart CGSL CORE 5.05 / MAIN 5.05 : httpd Multiple Vulnerabilities (NS-SA-2019-0250)NessusNewStart CGSL Local Security Checks
high
131476EulerOS Virtualization for ARM 64 3.0.3.0 : httpd (EulerOS-SA-2019-2311)NessusHuawei Local Security Checks
high
130866EulerOS 2.0 SP5 : httpd (EulerOS-SA-2019-2157)NessusHuawei Local Security Checks
medium
130711EulerOS 2.0 SP3 : httpd (EulerOS-SA-2019-2249)NessusHuawei Local Security Checks
medium
130540RHEL 8 : httpd:2.4 (RHSA-2019:3436)NessusRed Hat Local Security Checks
high
129922NewStart CGSL CORE 5.04 / MAIN 5.04 : httpd Multiple Vulnerabilities (NS-SA-2019-0202)NessusNewStart CGSL Local Security Checks
high
129439EulerOS 2.0 SP8 : httpd (EulerOS-SA-2019-2080)NessusHuawei Local Security Checks
medium
129017CentOS 7 : httpd (CESA-2019:2343)NessusCentOS Local Security Checks
high
128223Scientific Linux Security Update : httpd on SL7.x x86_64 (20190806)NessusScientific Linux Local Security Checks
high
127715RHEL 7 : httpd (RHSA-2019:2343)NessusRed Hat Local Security Checks
high
126777Oracle Enterprise Manager Ops Center (Jul 2019 CPU)NessusMisc.
critical
124541Fedora 30 : httpd (2019-cf7695b470)NessusFedora Local Security Checks
high
124264openSUSE Security Update : apache2 (openSUSE-2019-1258)NessusSuSE Local Security Checks
high
124125Amazon Linux 2 : httpd (ALAS-2019-1189)NessusAmazon Linux Local Security Checks
high
124102openSUSE Security Update : apache2 (openSUSE-2019-1209)NessusSuSE Local Security Checks
high
124017openSUSE Security Update : apache2 (openSUSE-2019-1190)NessusSuSE Local Security Checks
high
123958Amazon Linux AMI : httpd24 (ALAS-2019-1189)NessusAmazon Linux Local Security Checks
high
98530Apache 2.4.x < 2.4.39 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
high
700509Apache HTTP Server < 2.4.39 Multiple VulnerabilitiesNessus Network MonitorWeb Servers
high
123823SUSE SLES12 Security Update : apache2 (SUSE-SU-2019:0889-1)NessusSuSE Local Security Checks
high
123822SUSE SLES12 Security Update : apache2 (SUSE-SU-2019:0888-1)NessusSuSE Local Security Checks
high
123801Fedora 29 : httpd (2019-119b14075a)NessusFedora Local Security Checks
high
123787Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : apache2 vulnerabilities (USN-3937-1)NessusUbuntu Local Security Checks
high
123785SUSE SLES12 Security Update : apache2 (SUSE-SU-2019:0878-1)NessusSuSE Local Security Checks
high
123782SUSE SLED15 / SLES15 Security Update : apache2 (SUSE-SU-2019:0873-1)NessusSuSE Local Security Checks
high
123691Debian DSA-4422-1 : apache2 - security updateNessusDebian Local Security Checks
high
123689Debian DLA-1748-1 : apache2 security updateNessusDebian Local Security Checks
high
123644FreeBSD : Apache -- Multiple vulnerabilities (cf2105c6-551b-11e9-b95c-b499baebfeaf)NessusFreeBSD Local Security Checks
high
123642Apache 2.4.x < 2.4.39 Multiple VulnerabilitiesNessusWeb Servers
high