CyberRota Analysis
AI-GeneratedApache HTTP Server versions prior to 2.4.69 are vulnerable due to missing authentication checks in mod_auth_digest, allowing unauthenticated remote clients to trigger a denial of service by sending forged Authorization headers when Digest authentication is enabled. This vulnerability can lead to forced re-authentication, disrupting service availability. Administrators of affected Apache servers should prioritize upgrading to version 2.4.69 to mitigate this risk.
Original NVD Description
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)