Description
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Remediation
References
Related Vulnerabilities
WordPress Plugin Catch Breadcrumb Cross-Site Scripting (1.5.4)
WordPress Plugin Ultimate Google Analytics Cross-Site Request Forgery (1.6.0)
OpenSSL Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-2650)
WordPress Plugin Dynamic Widgets Multiple Unspecified Vulnerabilities (1.5.7)