CVE-2018-17199
30.01.2019, 22:29
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.0 ≤ 𝑥 ≤ 2.4.37 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| netapp | santricity_cloud_connector | - |
| netapp | storage_automation_store | - |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||||||||||||
| apache2-devel |
| ||||||||||||||||||||||||
| apache2-doc |
| ||||||||||||||||||||||||
| apache2-example-pages |
| ||||||||||||||||||||||||
| apache2-prefork |
| ||||||||||||||||||||||||
| apache2-utils |
| ||||||||||||||||||||||||
| apache2-worker |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References