In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
References
Configurations
History
07 Nov 2023, 03:01
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-04-08 20:29
Updated : 2024-02-28 17:08
NVD link : CVE-2019-0215
Mitre link : CVE-2019-0215
CVE.ORG link : CVE-2019-0215
JSON object : View
Products Affected
apache
- http_server
fedoraproject
- fedora
CWE