Description
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-2763 Vulnerability (CVE-2020-2763)
Oracle JRE CVE-2013-0440 Vulnerability (CVE-2013-0440)
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-18573)
Plone CMS Other Vulnerability (CVE-2006-1711)
WordPress Plugin WooCommerce Checkout Manager Cross-Site Request Forgery (4.3)