Description
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
Remediation
References
Related Vulnerabilities
WordPress Plugin Slimstat Analytics Cross-Site Scripting (4.9.2)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (2.8.4)
PHP Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2014-5459)
MongoDb Incorrect Authorization Vulnerability (CVE-2020-7921)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2018-1000861)