Input validation error in Apache HTTP Server - CVE-2019-0220
Published: April 2, 2019 / Updated: January 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to the web server does not merge consecutive slashes in URLs, that can lead to incorrect processing of requests when accessing CGI programs. Such web server behavior may lead to security restrictions bypass.
Affected software
JBoss Core Services
Red Hat Software Collections
apache2 (Alpine package)
apache2 (Debian package)
apache2 (Ubuntu package)
httpd
IBM API Connect
Dell Secure Connect Gateway
Oracle HTTP Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Data Computing Appliance (DCA)
Maximo Application Suite - IoT Component
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2019-0220
apache2 (Alpine package) - update to 2.4.39-r0
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
IBM API Connect - update to 5.0.8.12
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - addressed in versions 2.4.39-1.1.fc28, 2.4.39-2.fc29, 2.4.39-2.fc30
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Debian update for apache2
- Ubuntu update for Apache HTTP Server
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Red Hat update for httpd
- Red Hat update for httpd:2.4
- Red Hat Software Collections update for httpd24-httpd
- Red Hat JBoss Core Services update for Apache HTTP Server
- Input validation error in apache2 (Alpine package)
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Fedora 29 update for httpd
- Fedora 28 update for httpd
- Fedora 30 update for httpd