In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 27, 2017 |
| Amazon_linux | — | Upgrade httpd24 | Jan 20, 2017 | Dec 20, 2016 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 27, 2017 | Jul 27, 2017 |
| Apple Osx Apache | — | Apply OS X security update 2017-001 SierraUpgrade macOS to the latest versionApply OS X security update 2017-004 El Capitan | Mar 28, 2017 | Mar 28, 2017 |
| Centos_linux | — | Upgrade httpd-manualUpgrade mod_sessionUpgrade httpd-debuginfoUpgrade mod_ldapUpgrade mod_sslUpgrade httpdUpgrade httpd-develUpgrade httpd-toolsUpgrade mod_proxy_html | Apr 13, 2017 | Dec 20, 2016 |
| Debian | — | Upgrade apache2 | Feb 27, 2017 | Dec 20, 2016 |
| Freebsd | — | Upgrade apache24 | Dec 21, 2016 | Dec 21, 2016 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jul 27, 2017 |
| Hpux | — | Update hpuxws24APACHE.AUTH_LDAP2 to the latest versionUpdate hpuxws24APACHE.AUTH_LDAP to the latest versionUpdate hpuxws24APACHE.WEBPROXY to the latest versionUpdate hpuxws24APACHE.WEBPROXY2 to the latest versionUpdate hpuxws24APACHE.APACHE to the latest versionUpdate hpuxws24APACHE.MOD_PERL to the latest versionUpdate hpuxws24APACHE.MOD_JK to the latest versionUpdate hpuxws24APACHE.APACHE2 to the latest versionUpdate hpuxws24APACHE.MOD_PERL2 to the latest versionUpdate hpuxws24APACHE.MOD_JK2 to the latest version | Aug 11, 2017 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade httpd-toolsUpgrade httpd-manualUpgrade mod_sslUpgrade httpdUpgrade httpd-devel | Jan 18, 2018 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade httpd-manualUpgrade httpdUpgrade mod_sslUpgrade httpd-develUpgrade httpd-tools | Jan 18, 2018 | Jul 27, 2017 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.0.3 or later | Jun 22, 2018 | Jul 27, 2017 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-gss to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-lua to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Oracle_linux | — | Upgrade httpd-develUpgrade mod_proxy_htmlUpgrade mod_sslUpgrade mod_sessionUpgrade httpdUpgrade httpd-manualUpgrade mod_ldapUpgrade httpd-tools | Apr 13, 2017 | Dec 20, 2016 |
| Redhat_linux | — | Upgrade httpd-debuginfoUpgrade httpd-develUpgrade httpd-manualUpgrade httpd-toolsUpgrade httpdUpgrade mod_sslUpgrade mod_ldapUpgrade mod_proxy_htmlUpgrade mod_session | Apr 12, 2017 | Dec 20, 2016 |
| Suse | — | Upgrade apache2Upgrade apache2-develUpgrade apache2-utilsUpgrade apache2-eventUpgrade apache2-docUpgrade apache2-example-pagesUpgrade apache2-workerUpgrade apache2-prefork | Mar 23, 2017 | Dec 20, 2016 |
| Ubuntu | — | Upgrade apache2-bin | May 9, 2017 | Dec 20, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub