Security Advisory

CVE-2018-1312

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-26 15:00:00
Last updated 2024-09-16 19:14:07
Assigner apache
CVSS score not scored
State PUBLISHED

Description

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.