A privilege escalation vulnerability of important severity in the Apache HTTP server allows users with the right to write and run scripts to gain root on Unix systems was fixed in Apache httpd 2.4.39. The vulnerability was reported by security engineer Carles Fol on February 22, with a response and a patch being provided by Apache on March 7. Two other important severity control bypass security flaws were fixed in the. Apache HTTP Server 2.17-2.38 release, with the one tracked as CVE-2019-0217, enabling users “with valid credentials to authenticate using another username
Source: security

