Impact
Apache HTTP Server’s mod_auth_digest module allows a man‑in‑the‑middle attacker to capture a client’s digest authentication nonce and replay it in a crafted HTTP request. When AuthDigestNonceLifetime is set to 0, the replayed request triggers garbage collection of the client’s shared memory entry, effectively bypassing authentication. This vulnerability is a classic replay attack (CWE‑294) and can lead to unauthorized access to protected resources. The attacker can gain the same privileges as the victim without requiring credentials or local system access.
Affected Systems
The vulnerability affects all 2.4.x releases of Apache HTTP Server from the Apache Software Foundation. Versions prior to 2.4.69 contain the flaw; version 2.4.69 and later include the fix.
Risk and Exploitability
The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, indicating no known public exploitation at this time. The attack vector requires the attacker to be able to intercept HTTP traffic (typical for a man‑in‑the‑middle or compromised network device). Once the credential is captured, replaying it is straightforward without additional privileges. The lack of a CVSS score in the available data limits precise severity quantification, but the ability to bypass authentication and the straightforward exploitation path suggest a moderate to high risk for exposed services. Prompt remediation via patching is strongly advised.
OpenCVE Enrichment