CVE-2018-17199

All FrameworksApache HTTPDCWE-OtherCVE-2018-17199

CVE-2018-17199

State: PUBLISHED · Published: 2019-01-30 · Updated: 2024-09-16 · Assigner: apache
Description
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2018/17xxx/CVE-2018-17199.json