Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-17199

Опубликовано: 30 янв. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

РелизСтатусПримечание
bionic

released

2.4.29-1ubuntu4.6
cosmic

released

2.4.34-1ubuntu2.1
devel

not-affected

2.4.38-2ubuntu1
esm-infra-legacy/trusty

not-affected

2.4.7-1ubuntu4.22
esm-infra/bionic

not-affected

2.4.29-1ubuntu4.6
esm-infra/xenial

not-affected

2.4.18-2ubuntu3.10
precise/esm

not-affected

code not present
trusty

released

2.4.7-1ubuntu4.22
trusty/esm

not-affected

2.4.7-1ubuntu4.22
upstream

released

2.4.38-1

Показывать по

EPSS

Процентиль: 90%
0.06251
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
больше 6 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS3: 7.5
nvd
больше 6 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS3: 7.5
debian
больше 6 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks ...

CVSS3: 7.5
github
около 3 лет назад

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость модуля mod_session веб-сервера Apache HTTP Server, связанная с отсутствием учета времени жизни сеанса, позволяющая нарушителю оказать воздействие на целостность защищаемых данных

EPSS

Процентиль: 90%
0.06251
Низкий

5 Medium

CVSS2

7.5 High

CVSS3