In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 27, 2017 |
| Amazon_linux | — | Upgrade httpd24 | Jan 20, 2017 | Dec 20, 2016 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 27, 2017 | Jul 27, 2017 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2017-001 SierraApply OS X security update 2017-004 El Capitan | Mar 28, 2017 | Mar 28, 2017 |
| Centos_linux | — | Upgrade httpd-manualUpgrade mod_sslUpgrade mod_ldapUpgrade httpd-debuginfoUpgrade mod_sessionUpgrade httpd-develUpgrade httpdUpgrade httpd-toolsUpgrade mod_proxy_html | Apr 13, 2017 | Dec 20, 2016 |
| Debian | — | Upgrade apache2 | Feb 27, 2017 | Dec 20, 2016 |
| Freebsd | — | Upgrade apache24 | Dec 21, 2016 | Dec 21, 2016 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jul 27, 2017 |
| Hpux | — | Update hpuxws24APACHE.APACHE to the latest versionUpdate hpuxws24APACHE.WEBPROXY2 to the latest versionUpdate hpuxws24APACHE.WEBPROXY to the latest versionUpdate hpuxws24APACHE.AUTH_LDAP to the latest versionUpdate hpuxws24APACHE.AUTH_LDAP2 to the latest versionUpdate hpuxws24APACHE.MOD_JK to the latest versionUpdate hpuxws24APACHE.MOD_PERL to the latest versionUpdate hpuxws24APACHE.MOD_PERL2 to the latest versionUpdate hpuxws24APACHE.APACHE2 to the latest versionUpdate hpuxws24APACHE.MOD_JK2 to the latest version | Aug 11, 2017 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade httpd-toolsUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-develUpgrade httpd | Jan 18, 2018 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade httpd-toolsUpgrade httpdUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-devel | Jan 18, 2018 | Jul 27, 2017 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.0.3 or later | Jun 22, 2018 | Jul 27, 2017 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-ssl to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-gss to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-lua to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Oracle_linux | — | Upgrade httpd-manualUpgrade httpd-toolsUpgrade mod_ldapUpgrade mod_sslUpgrade httpdUpgrade mod_sessionUpgrade httpd-develUpgrade mod_proxy_html | Apr 13, 2017 | Dec 20, 2016 |
| Redhat_linux | — | Upgrade mod_proxy_htmlUpgrade mod_ldapUpgrade mod_sslUpgrade mod_sessionUpgrade httpd-manualUpgrade httpd-debuginfoUpgrade httpdUpgrade httpd-develUpgrade httpd-tools | Apr 12, 2017 | Dec 20, 2016 |
| Suse | — | Upgrade apache2-example-pagesUpgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-develUpgrade apache2-eventUpgrade apache2-utilsUpgrade apache2-docUpgrade apache2 | Mar 23, 2017 | Dec 20, 2016 |
| Ubuntu | — | Upgrade apache2-bin | May 9, 2017 | Dec 20, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub