peter bassill · operator
$ cve CVE-2019-0211 JSON

CVE-2019-0211 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 65% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS65.01% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2019-04-08
Last modified2026-06-17

CISA KEV

NameApache HTTP Server Privilege Escalation Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productApache / HTTP Server
Ransomware usenone reported

Affected (27)

VendorProduct
apachehttp server
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
netapponcommand unified manager
opensuseleap
oraclecommunications session report manager
oraclecommunications session route manager
oracleenterprise manager ops center
oraclehttp server
oracleinstantis enterprisetrack
oracleretail xstore point of service
redhatenterprise linux
redhatenterprise linux eus
redhatenterprise linux for arm 64
redhatenterprise linux for arm 64 eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux update services for sap solutions
redhatjboss core services
redhatopenshift container platform
redhatopenshift container platform for power
redhatsoftware collections

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD