In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
References
Configurations
History
No history.
Information
Published : 2019-04-08 20:29
Updated : 2023-11-07 03:01
NVD link : CVE-2019-0215
Mitre link : CVE-2019-0215
CVE.ORG link : CVE-2019-0215
JSON object : View
Products Affected
apache
- http_server
fedoraproject
- fedora
CWE