Impact
Use after free vulnerability in mod_auth_digest allows an unauthenticated remote client to corrupt authentication state by sending concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.
Affected Systems
Apache Software Foundation Apache HTTP Server versions prior to 2.4.69 on all platforms are affected.
Risk and Exploitability
The flaw can be exploited by any remote client that can send Digest authentication requests, potentially causing denial of service through corrupted state. No exploit probability score is available, and the vulnerability is not listed in CISA KEV. The impact is significant for systems relying on Digest authentication.
OpenCVE Enrichment