5.3
CVSSv3

CVE-2019-0220

Published: 11/06/2019 Updated: 21/11/2024

Vulnerability Summary

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server

opensuse leap 15.0

opensuse leap 42.3

debian debian linux 8.0

debian debian linux 9.0

fedoraproject fedora 28

fedoraproject fedora 29

fedoraproject fedora 30

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

Several security issues were fixed in the Apache HTTP Server ...
Several vulnerabilities have been found in the Apache HTTP server CVE-2018-17189 Gal Goldshtein of F5 Networks discovered a denial of service vulnerability in mod_http2 By sending malformed requests, the http/2 stream for that request unnecessarily occupied a server thread cleaning up incoming data, resulting in denial of service ...
Debian Bug report logs - #920302 apache2: CVE-2018-17189: mod_http2, DoS via slow, unneeded request bodies Package: src:apache2; Maintainer for src:apache2 is Debian Apache Maintainers <debian-apache@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 23 Jan 2019 20:33:05 UTC Severity: ...
Debian Bug report logs - #920303 apache2: CVE-2018-17199: mod_session_cookie does not respect expiry time Package: src:apache2; Maintainer for src:apache2 is Debian Apache Maintainers <debian-apache@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 23 Jan 2019 20:36:02 UTC Severity: ...
Synopsis Moderate: httpd24-httpd security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for httpd24, httpd24-httpd, and httpd24-nghttp2 is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Low: Red Hat JBoss Core Services Apache HTTP Server 2437 SP1 Security Update Type/Severity Security Advisory: Low Topic Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2437 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise L ...
Synopsis Moderate: httpd:24 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for the httpd:24 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring S ...
Synopsis Low: Red Hat JBoss Core Services Apache HTTP Server 2437 SP1 Security Update Type/Severity Security Advisory: Low Topic Red Hat JBoss Core Services Pack Apache Server 2437 Service Pack 1 zip release for RHEL 6, RHEL 7 and Microsoft Windows is availableRed Hat Product Security has rated this up ...
Synopsis Moderate: httpd security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for httpd is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base s ...
In Apache HTTP Server with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard (CVE-2019-0211) A vulnerability was found in ...
In Apache HTTP Server with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard (CVE-2019-0211) mod_http2: read-after-free on ...
Severity Unknown Remote Unknown Type Unknown Description AVG-946 apache 2438-1 2439-1 Medium Testing ...
A vulnerability (CVE-2019-0220) exists in Cosminexus HTTP Server and Hitachi Web Server Affected products and versions are listed below Please upgrade your version to the appropriate version ...

Mailing Lists

CVE-2019-0220: URL normalization inconsistincies Severity: Low Vendor: The Apache Software Foundation Versions Affected: httpd 240 to 2439 Description: When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions whil ...

Github Repositories

this topic includes Reconnaissance and planning, Google Dorking, certificate transparency, shodan & recon-ng

Introduction-to-Pentesting-and-OSINT Objectives of this article: Understand the role of a pentester in assessing a business's security Collect domain information using OSINT techniques and tools like Google dorking, Shodan, and certificate transparency Use Shodan and Recon-ng to discover domain server information PLEASE DO NOT practice these techniques against compute