CyberSec.Space Logo
Back to CVE Browser

CVE-2018-1312

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0540%
EPSS Percentile20.77th
PublishedMar 26, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

Affected Platforms (CPE)

πŸ“¦
Apache

Http Server

= 2.4.1
πŸ“¦
Apache

Http Server

= 2.4.2
πŸ“¦
Apache

Http Server

= 2.4.3
πŸ“¦
Apache

Http Server

= 2.4.4
πŸ“¦
Apache

Http Server

= 2.4.6
πŸ“¦
Apache

Http Server

= 2.4.7
πŸ“¦
Apache

Http Server

= 2.4.9
πŸ“¦
Apache

Http Server

= 2.4.10
πŸ“¦
Apache

Http Server

= 2.4.12
πŸ“¦
Apache

Http Server

= 2.4.16
πŸ“¦
Apache

Http Server

= 2.4.17
πŸ“¦
Apache

Http Server

= 2.4.18
πŸ“¦
Apache

Http Server

= 2.4.20
πŸ“¦
Apache

Http Server

= 2.4.23
πŸ“¦
Apache

Http Server

= 2.4.25
πŸ“¦
Apache

Http Server

= 2.4.26
πŸ“¦
Apache

Http Server

= 2.4.27
πŸ“¦
Apache

Http Server

= 2.4.28
πŸ“¦
Apache

Http Server

= 2.4.29
πŸ’»
Canonical

Ubuntu Linux

= 12.04
πŸ’»
Canonical

Ubuntu Linux

= 14.04
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ’»
Canonical

Ubuntu Linux

= 17.10
πŸ’»
Canonical

Ubuntu Linux

= 18.04
πŸ’»
Debian

Debian Linux

= 7.0
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ“¦
Netapp

Cloud Backup

All versions
πŸ“¦
Netapp

Storagegrid

All versions
πŸ’»
Netapp

Clustered Data Ontap

All versions
πŸ“¦
Redhat

Jboss Core Services

= 1.0
πŸ’»
Redhat

Enterprise Linux Desktop

= 7.0
πŸ’»
Redhat

Enterprise Linux Eus

= 7.6
πŸ’»
Redhat

Enterprise Linux Server

= 7.0
πŸ’»
Redhat

Enterprise Linux Server Aus

= 7.6
πŸ’»
Redhat

Enterprise Linux Server Tus

= 7.6
πŸ’»
Redhat

Enterprise Linux Workstation

= 7.0

References & Advisories

Related Vulnerabilities