CVE-2019-0211

HIGHCVSS 7.8/10Actively ExploitedEPSS 65.00%

Last modified

CVE-2019-0211 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.. CISA has confirmed active exploitation in the wild. EPSS estimates a 65.00% chance of exploitation in the next 30 days.

Description

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
65.00%

99.1th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheHttp Server>= 2.4.17, <= 2.4.38
FedoraprojectFedora28
FedoraprojectFedora29
FedoraprojectFedora30
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux18.10
DebianDebian Linux9.0
OpensuseLeap15.0
OpensuseLeap42.3
NetappOncommand Unified ManagerAll versions
RedhatJboss Core Services1.0
RedhatOpenshift Container Platform3.11
RedhatOpenshift Container Platform For Power3.11_ppc64le
RedhatSoftware Collections1.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus8.1
RedhatEnterprise Linux Eus8.2
RedhatEnterprise Linux Eus8.4
RedhatEnterprise Linux Eus8.6
RedhatEnterprise Linux Eus8.8
RedhatEnterprise Linux For Arm 648.0_aarch64
RedhatEnterprise Linux For Arm 64 Eus8.1_aarch64
RedhatEnterprise Linux For Arm 64 Eus8.2_aarch64
RedhatEnterprise Linux For Arm 64 Eus8.4_aarch64
RedhatEnterprise Linux For Arm 64 Eus8.6_aarch64
RedhatEnterprise Linux For Arm 64 Eus8.8_aarch64
RedhatEnterprise Linux For Ibm Z Systems8.0_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus8.1_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus8.2_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus8.4_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus8.6_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus8.8_s390x
RedhatEnterprise Linux For Power Little Endian8.0_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus8.1_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus8.2_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus8.4_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus8.6_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus8.8_ppc64le
RedhatEnterprise Linux Server Aus8.2
RedhatEnterprise Linux Server Aus8.4
RedhatEnterprise Linux Server Aus8.6
RedhatEnterprise Linux Server Tus8.2
RedhatEnterprise Linux Server Tus8.4
RedhatEnterprise Linux Server Tus8.6
RedhatEnterprise Linux Server Tus8.8
RedhatEnterprise Linux Update Services For Sap Solutions8.0
RedhatEnterprise Linux Update Services For Sap Solutions8.1
RedhatEnterprise Linux Update Services For Sap Solutions8.4

Showing 50 of 68 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2019-0211?
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
How severe is CVE-2019-0211?
CVE-2019-0211 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 65.00% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2019-0211?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-0211?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST