Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- <= 2.4.66
A timing attack vulnerability has been identified in the mod_auth_digest module of Apache HTTP Server versions through 2.4.66. This vulnerability allows a remote attacker to bypass Digest authentication. The issue arises from the way authentication timing is handled, creating a potential window for exploitation.
Exploitation of this vulnerability allows for bypassing Digest authentication, potentially leading to unauthorized access.
Users are advised to upgrade to Apache HTTP Server version 2.4.67, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.