CVE-2019-0215
EUVD-2019-100308.04.2019, 20:29
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.37 |
| apache | http_server | 2.4.38 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References