Input validation error in Apache HTTP Server - CVE-2019-0220

 

Input validation error in Apache HTTP Server - CVE-2019-0220

Published: April 2, 2019 / Updated: January 29, 2020


Vulnerability identifier: #VU18113
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0220
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to the web server does not merge consecutive slashes in URLs, that can lead to incorrect processing of requests when accessing CGI programs. Such web server behavior may lead to security restrictions bypass.


Affected software

Apache HTTP Server
JBoss Core Services
Red Hat Software Collections
apache2 (Alpine package)
apache2 (Debian package)
apache2 (Ubuntu package)
httpd
IBM API Connect
Dell Secure Connect Gateway
Oracle HTTP Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Data Computing Appliance (DCA)
Maximo Application Suite - IoT Component
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)

How to mitigate CVE-2019-0220

Install updates from vendor's website and make sure that "MergeSlashes" option in the configuration is not set to "Off".

Apache HTTP Server - update to 2.4.39
apache2 (Alpine package) - update to 2.4.39-r0
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
IBM API Connect - update to 5.0.8.12
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - addressed in versions 2.4.39-1.1.fc28, 2.4.39-2.fc29, 2.4.39-2.fc30
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins