Also, I just want to throw out there that the name of this one is great:
"Why the name ? CARPE: stands for CVE-2019-0211 Apache Root Privilege Escalation DIEM: the exploit triggers once a day
I had to."
Usually when a range like that is given, yes.
> From version 2.4.17 (Oct 9, 2015) to version 2.4.38 (Apr 1, 2019)
This case implies that they know the bug was introduced in a particular change, which went public with version 2.4.17 and was either fixed or otherwise mitigated in 2.4.38.
The only earlier or other versions that I would expect to see affected are dev/alpha/beta branches.
> Apache's team has been prompt to respond and patch, and nice as hell. Really good experience. PHP never answered regarding the UAF.
I expect that it'll be fixed, not not handled as a security issue, as it doesn't fit within PHPs model of security vulns.
I'm not sure how I feel about such a response. Many exploits require odd, but valid code, and more often than not it exists out there.
Also, it feels weird for this to be tagged as a JSON issue?