In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
References
Information
Published : 2019-04-08 13:29
Updated : 2021-06-06 04:15
NVD link : CVE-2019-0215
Mitre link : CVE-2019-0215
JSON object : View
CWE
Products Affected
apache
- http_server
fedoraproject
- fedora