CVE Vulnerabilities

CVE-2018-1312

Improper Authentication

Published: Mar 26, 2018 | Modified: Jun 17, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
4.2 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache2.4.1 (including)2.4.1 (including)
Http_serverApache2.4.2 (including)2.4.2 (including)
Http_serverApache2.4.3 (including)2.4.3 (including)
Http_serverApache2.4.4 (including)2.4.4 (including)
Http_serverApache2.4.6 (including)2.4.6 (including)
Http_serverApache2.4.7 (including)2.4.7 (including)
Http_serverApache2.4.9 (including)2.4.9 (including)
Http_serverApache2.4.10 (including)2.4.10 (including)
Http_serverApache2.4.12 (including)2.4.12 (including)
Http_serverApache2.4.16 (including)2.4.16 (including)
Http_serverApache2.4.17 (including)2.4.17 (including)
Http_serverApache2.4.18 (including)2.4.18 (including)
Http_serverApache2.4.20 (including)2.4.20 (including)
Http_serverApache2.4.23 (including)2.4.23 (including)
Http_serverApache2.4.25 (including)2.4.25 (including)
Http_serverApache2.4.26 (including)2.4.26 (including)
Http_serverApache2.4.27 (including)2.4.27 (including)
Http_serverApache2.4.28 (including)2.4.28 (including)
Http_serverApache2.4.29 (including)2.4.29 (including)
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-0:1-6.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-apr-0:1.6.3-31.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-httpd-0:2.4.29-35.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el6*
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el6*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-0:1-6.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-apr-0:1.6.3-31.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-httpd-0:2.4.29-35.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el7*
Red Hat Enterprise Linux 7RedHathttpd-0:2.4.6-89.el7_6.1*
Red Hat JBoss Core ServicesRedHathttpd*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-curl-0:7.61.1-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-httpd-0:2.4.34-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-nghttp2-0:1.7.1-7.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-curl-0:7.61.1-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-httpd-0:2.4.34-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHathttpd24-nghttp2-0:1.7.1-7.el7*
Apache2Ubuntuartful*
Apache2Ubuntubionic*
Apache2Ubuntucosmic*
Apache2Ubuntudevel*
Apache2Ubuntuesm-infra-legacy/trusty*
Apache2Ubuntuesm-infra-legacy/xenial*
Apache2Ubuntuesm-infra/bionic*
Apache2Ubuntuesm-infra/xenial*
Apache2Ubuntutrusty*
Apache2Ubuntutrusty/esm*
Apache2Ubuntuupstream*
Apache2Ubuntuxenial*

Potential Mitigations

References