CVE-2019-0215
08.04.2019, 20:29
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.37 |
| apache | http_server | 2.4.38 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References