Apache HTTP Server < 2.4.38 - Authentication Bypass via Race Condition in mod_auth_digest
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-0217. PoCs published by savsch.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2019-0217, which leverages a race condition in Apache HTTP Server's mod_auth_digest to bypass authentication controls. The exploit uses Burp Suite's Turbo Intruder to send concurrent requests with forged and valid authentication headers.
Description
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2019-0217, which leverages a race condition in Apache HTTP Server's mod_auth_digest to bypass authentication controls. The exploit uses Burp Suite's Turbo Intruder to send concurrent requests with forged and valid authentication headers.
References (39)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H