CVE-2019-0217: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 17.4% chance of exploitation in the next 30 days.

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

Affected products

  • Apache HTTP Server: from 2.4.0, up to and including 2.4.38
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp Oncommand Unified Manager: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 42.3 only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle HTTP Server: version 12.2.1.3.0 only
  • Oracle Retail Xstore Point Of Service: version 7.0 only; version 7.1 only
  • Red Hat Enterprise Linux: affected versions not specified
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2019-04-08. Last modified 2026-06-17.