New Apache Web Server Bug Threatens Security of Shared Web Hosts

apache web server security vulnerability

Mark J Cox, one of the founding members of the Software Foundation and the OpenSSL project, today posted a tweet warning users about a recently discovered important flaw in Apache HTTP Server software.

The Apache web is one of the most popular, widely used open-source web servers in the world that powers almost 40 percent of the whole Internet.

The vulnerability, identified as CVE-2019-0211, was discovered by Charles Fol, a security engineer at Ambionics Security firm, and patched by the Apache developers in the latest version 2.4.39 of its software released today.

The flaw affects Apache HTTP Server versions 2.4.17 through 2.4.38 and could allow any less-privileged user to execute arbitrary code with root privileges on the targeted server.

“In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected,” the advisory says.

According to Cox, the vulnerability is more concerning for web hosting services, where malicious customers or a hacker with ability to execute PHP or CGI scripts on a website can make use of the flaw to gain root access on the server, eventually compromising all other websites hosted on the same server.

Besides this, the latest Apache httpd 2.4.39 version also patches three low and two other important severity .

The second important flaw (CVE-2019-0217) could allow “a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.”

Also Read:  Microsoft Releases April 2019 Security Updates Two Flaws Under Active Attack

The third vulnerability is a mod_ssl access control bypass (CVE-2019-0215), “a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client supporting Post-Handshake Authentication to bypass configured access control restrictions.”

We have seen how previous disclosures of severe in web application frameworks have resulted in PoC exploits being published within a day and in the wild, putting critical infrastructure as well as customers’ at risk.

Therefore, web hosting services, organizations managing their own servers and website administrators are strongly advised to upgrade their Apache HTTP instances to the latest versions as soon as possible.


You might also like More from author

Comments are closed.