Description
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
Remediation
References
Related Vulnerabilities
WordPress Plugin Per page add to head Cross-Site Request Forgery (1.4.3)
Oracle JRE CVE-2013-0351 Vulnerability (CVE-2013-0351)
MySQL CVE-2022-21309 Vulnerability (CVE-2022-21309)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7874)
WordPress Plugin Mapplic-Custom Interactive Map Server-Side Request Forgery (6.1)