CyberRota Analysis
AI-GeneratedThe Apache HTTP Server prior to version 2.4.69 is vulnerable to a use-after-free flaw in the mod_auth_digest module, which can lead to authentication state corruption when concurrent Digest authentication requests are made with specific configurations. This vulnerability allows unauthenticated remote clients to exploit the issue, potentially compromising the integrity of authentication processes. Organizations using affected versions, especially those with AuthDigestNcCheck enabled or AuthDigestNonceLifetime set to 0, should prioritize upgrading to version 2.4.69 to mitigate the risk.
Original NVD Description
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)