VYPR
High severity7.5NVD Advisory· Published Apr 8, 2019· Updated Jun 17, 2026

CVE-2019-0215

CVE-2019-0215

Description

In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:apache:http_server:2.4.37:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:http_server:2.4.37:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.4.38:*:*:*:*:*:*:*
    • (no CPE)range: 2.4.37, 2.4.38
    • (no CPE)range: 2.4.37
  • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

29

News mentions

0

No linked articles in our index yet.