Description
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
Remediation
References
Related Vulnerabilities
Apache Tomcat Other Vulnerability (CVE-2007-3383)
Oracle Database Server CVE-2015-0483 Vulnerability (CVE-2015-0483)
WordPress Plugin Weather Effect-Christmas Santa Snow Falling Cross-Site Request Forgery (1.3.3)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3464)
WordPress Plugin WP Page Builder Multiple Vulnerabilities (1.2.3)