CyberRota Analysis
AI-GeneratedThe Apache HTTP Server 2.4.x is vulnerable to an authentication bypass due to a capture-replay flaw in the mod_auth_digest module, which allows a man-in-the-middle attacker to exploit captured digest credentials. This vulnerability can be triggered when the AuthDigestNonceLifetime is set to 0, enabling unauthorized access through crafted requests. Organizations using affected versions should prioritize upgrading to version 2.4.69 to mitigate this risk.
Original NVD Description
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)