In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
We have discovered 727,573 live websites that are affected by CVE-2018-17199.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 727,573 live websites (26% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 31 versions ( 26% of all versions) |
| 227,856 websites | |
| 65,396 websites | |
| 41,594 websites | |
| 38,503 websites | |
| 30,797 websites | |
| 29,549 websites | |
| 22,930 websites | |
| 22,480 websites | |
| 21,541 websites | |
| 19,835 websites |
| .com | 285,135 websites |
| .de | 41,145 websites |
| .org | 32,451 websites |
| .net | 28,317 websites |
| .ru | 26,802 websites |
| .nl | 21,239 websites |
| .it | 20,544 websites |
| .cz | 17,557 websites |
| .jp | 16,808 websites |
| .fr | 13,691 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.***.****.****.************.net | *** | ||
| *********.net | *** | ||
| ***.****.us | *,*** | ||
| ******************.com | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| *****.com | *,*** | ||
| ********.in | *,*** | ||
| ******.*****.gov | *,*** | ||
| ******.de | *,*** |