CVE-2019-0217

HIGH LAB

Apache HTTP Server < 2.4.38 - Authentication Bypass via Race Condition in mod_auth_digest

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-0217. PoCs published by savsch.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2019-0217, which leverages a race condition in Apache HTTP Server's mod_auth_digest to bypass authentication controls. The exploit uses Burp Suite's Turbo Intruder to send concurrent requests with forged and valid authentication headers.

Description

In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

Exploits (1)

nomisec WORKING POC
by savsch · poc
https://github.com/savsch/PoC_CVE-2019-0217

This repository contains a proof-of-concept exploit for CVE-2019-0217, which leverages a race condition in Apache HTTP Server's mod_auth_digest to bypass authentication controls. The exploit uses Burp Suite's Turbo Intruder to send concurrent requests with forged and valid authentication headers.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Racy
Target: Apache HTTP Server 2.4.38 and prior
Auth required
Prerequisites: Valid credentials for an attacker account · Known username of the victim account · Access to a vulnerable Apache HTTP Server instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (39)

Core 39
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/04/02/5
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107668
Issue Tracking, Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Apr/5
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/04/msg00008.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3937-1/
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4422
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1695020
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3937-2/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00051.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00061.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190423-0001/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00084.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2343
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3436
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3933
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3935
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3932
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:4126

Scores

CVSS v3 7.5
EPSS 0.1767
EPSS Percentile 96.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull bitnami/minideb:latest

Details

CWE
CWE-362
Status published
Products (24)
apache/http_server 2.4.0 - 2.4.38
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
debian/debian_linux 8.0
debian/debian_linux 9.0
fedoraproject/fedora 28
fedoraproject/fedora 29
... and 14 more
Published Apr 08, 2019
Tracked Since Feb 18, 2026