Description
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2158)
CrushFTP Server Deserialization of Untrusted Data Vulnerability (CVE-2017-14035)
WordPress 6.1.x Multiple Vulnerabilities (6.1 - 6.1.3)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-5447)