In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
We have discovered 136,064 live websites that are affected by CVE-2019-0215.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 136,064 live websites (4.80% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 2 versions ( 1.68% of all versions) |
| 34,458 websites | |
| 15,580 websites | |
| 11,680 websites | |
| 10,889 websites | |
| 6,660 websites | |
| 5,727 websites | |
| 4,846 websites | |
| 4,058 websites | |
| 3,117 websites |
| .com | 47,178 websites |
| .jp | 10,789 websites |
| .de | 6,551 websites |
| .org | 6,012 websites |
| .ru | 5,205 websites |
| .net | 4,471 websites |
| .it | 4,253 websites |
| .edu | 3,941 websites |
| .co.uk | 3,701 websites |
| .fr | 3,503 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| *************.***.****.****.************.net | *** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** | ||
| *******.org | *,*** | ||
| *****.com | *,*** | ||
| ******.*****.gov | *,*** | ||
| ***.**.uk | *,*** | ||
| ***********************.com | *,*** | ||
| ***.***.org | *,*** |