CVE-2020-13938
Summary
| CVE | CVE-2020-13938 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-10 07:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Application | Apache | Http Server | All | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | All | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | - | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_1 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_10 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_11 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_12 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_2 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_3 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_4 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_5 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_6 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_7 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_8 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_9 | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Netapp | Cloud Backup | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MLIST | lists.apache.org | |
| Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | CONFIRM | httpd.apache.org | |
| Pony Mail! | CONFIRM | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| June 2021 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Pony Mail! | lists.apache.org | ||
| oss-security - CVE-2020-13938: Apache httpd: Improper Handling of Insufficient Privileges | MLIST | www.openwall.com | |
| [httpd-dev] 20210610 Re: svn commit: r1890598 - in /httpd/site/trunk/content/security/json: CVE-2019-17567.json CVE-2020-13938.json CVE-2020-13950.json CVE-2020-35452.json CVE-2021-26690.json CVE-2021-26691.json CVE-2021-30641.json CVE-2021-31618.json | lists.apache.org | ||
| Security Bulletin - ePolicy Orchestrator update addresses multiple product vulnerabilities (CVE-2022-0842, CVE-2022-0857, CVE-2022-0858, CVE-2022-0859, CVE-2022-0861, CVE-2022-0862) and updates Java, Apache HTTP Server, and Tomcat | CONFIRM | kc.mcafee.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Discovered by Ivan Zhakov
Legacy QID Mappings
- 352395 Amazon Linux Security Advisory for httpd: ALAS2-2021-1659
- 352462 Amazon Linux Security Advisory for httpd: ALAS2-2021-1674
- 352477 Amazon Linux Security Advisory for httpd24: ALAS-2021-1514
- 375955 IBM Security SiteProtector System Apache Hypertext Transfer Protocol (HTTP) Server Vulnerabilities
- 500021 Alpine Linux Security Update for apache2
- 503712 Alpine Linux Security Update for apache2
- 590870 Mitsubishi Electric MELSOFT iQ AppPortal Multiple Vulnerabilities (ICSA-22-132-02)
- 690107 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (cce76eca-ca16-11eb-9b84-d4c9ef517024)
- 730109 Apache HTTP Server Multiple Vulnerabilities
- 87451 IBM HTTP Server Multiple Vulnerabilities (6464029)