Related Vulnerabilities: CVE-2018-1312  

In Apache httpd 2.2.0 before 2.4.30, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

Severity Low

Remote Yes

Type Content spoofing

Description

In Apache httpd 2.2.0 before 2.4.30, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

AVG-664 apache 2.4.29-1 2.4.33-1 Medium Fixed

04 Apr 2018 ASA-201804-4 AVG-664 apache Medium multiple issues