Description
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Remediation
References
Related Vulnerabilities
WordPress Plugin LB Mixed Slideshow 'upload.php' Arbitrary File Upload (1.0)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Security Bypass (3.10.15)
Oracle Application Server CVE-2006-5359 Vulnerability (CVE-2006-5359)
Caddy Web Server Out-of-bounds Read Vulnerability (CVE-2022-34037)