Description
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Remediation
References
Related Vulnerabilities
PHP Resource Management Errors Vulnerability (CVE-2015-8877)
WordPress 4.3.x Prototype Pollution (4.3 - 4.3.27)
WordPress Plugin Header Footer Code Manager SQL Injection (1.1.13)
WordPress Plugin Permalink Manager Lite Cross-Site Scripting (2.2.14)
WordPress Plugin Contact Form 7 Arbitrary File Upload (5.3.1)