CVE-2019-0211: Apache HTTP Server Privilege Escalation Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 65% chance of exploitation in the next 30 days.

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Affected products

  • Apache HTTP Server: from 2.4.17, up to and including 2.4.38
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Netapp Oncommand Unified Manager: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 42.3 only
  • Oracle Communications Session Report Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Session Route Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle HTTP Server: version 12.2.1.3.0 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle Retail Xstore Point Of Service: version 7.0 only; version 7.1 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only
  • Red Hat Enterprise Linux For Arm 64: version 8.0_aarch64 only
  • Red Hat Enterprise Linux For Arm 64 Eus: version 8.1_aarch64 only; version 8.2_aarch64 only; version 8.4_aarch64 only; version 8.6_aarch64 only; version 8.8_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.1_s390x only; version 8.2_s390x only; version 8.4_s390x only; version 8.6_s390x only; version 8.8_s390x only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.1_ppc64le only; version 8.2_ppc64le only; version 8.4_ppc64le only; version 8.6_ppc64le only; version 8.8_ppc64le only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only
  • Red Hat Enterprise Linux Update Services For SAP Solutions: version 8.0 only; version 8.1 only; version 8.4 only; version 8.6 only; version 8.8 only
  • Red Hat JBoss Core Services: version 1.0 only
  • Red Hat Openshift Container Platform: version 3.11 only
  • and 2 more

Published 2019-04-08. Last modified 2026-06-17.