Skip to content

Apache 2.4.18 — Vulnerabilities [new]

: The nonce used in HTTP Digest authentication is not generated with a secure random seed, allowing attackers to replay requests across a cluster.

(affect 2.4.18 indirectly via later patches) apache 2.4.18 vulnerabilities