CVE Vulnerabilities

CVE-2018-1312

Improper Authentication

Published: Mar 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
4.2 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache2.4.1 (including)2.4.1 (including)
Http_serverApache2.4.2 (including)2.4.2 (including)
Http_serverApache2.4.3 (including)2.4.3 (including)
Http_serverApache2.4.4 (including)2.4.4 (including)
Http_serverApache2.4.6 (including)2.4.6 (including)
Http_serverApache2.4.7 (including)2.4.7 (including)
Http_serverApache2.4.9 (including)2.4.9 (including)
Http_serverApache2.4.10 (including)2.4.10 (including)
Http_serverApache2.4.12 (including)2.4.12 (including)
Http_serverApache2.4.16 (including)2.4.16 (including)
Http_serverApache2.4.17 (including)2.4.17 (including)
Http_serverApache2.4.18 (including)2.4.18 (including)
Http_serverApache2.4.20 (including)2.4.20 (including)
Http_serverApache2.4.23 (including)2.4.23 (including)
Http_serverApache2.4.25 (including)2.4.25 (including)
Http_serverApache2.4.26 (including)2.4.26 (including)
Http_serverApache2.4.27 (including)2.4.27 (including)
Http_serverApache2.4.28 (including)2.4.28 (including)
Http_serverApache2.4.29 (including)2.4.29 (including)
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-0:1-6.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-apr-0:1.6.3-31.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-httpd-0:2.4.29-35.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el6*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-0:1-6.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-apr-0:1.6.3-31.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-httpd-0:2.4.29-35.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el7*
Red Hat Enterprise Linux 7RedHathttpd-0:2.4.6-89.el7_6.1*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-curl-0:7.61.1-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-httpd-0:2.4.34-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-nghttp2-0:1.7.1-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Text-Only JBCSRedHathttpd*
Apache2Ubuntuartful*
Apache2Ubuntubionic*
Apache2Ubuntucosmic*
Apache2Ubuntudevel*
Apache2Ubuntuesm-infra-legacy/trusty*
Apache2Ubuntuesm-infra/bionic*
Apache2Ubuntuesm-infra/xenial*
Apache2Ubuntutrusty*
Apache2Ubuntutrusty/esm*
Apache2Ubuntuupstream*
Apache2Ubuntuxenial*

Potential Mitigations

References