CVE-2018-1312: Apache HTTP Server
Critical severity, CVSS 9.8. EPSS: 15.7% chance of exploitation in the next 30 days.
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
Affected products
- Apache HTTP Server: version 2.4.1 only; version 2.4.2 only; version 2.4.3 only; version 2.4.4 only; version 2.4.6 only; version 2.4.7 only; …
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Netapp Cloud Backup: affected versions not specified
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Storagegrid: affected versions not specified
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Eus: version 7.6 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Tus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Red Hat JBoss Core Services: version 1.0 only
Published 2018-03-26. Last modified 2026-06-17.