Описание
A flaw was found in the mod_auth_digest module of the Apache HTTP Server. This vulnerability allows an attacker positioned on the network to bypass authentication by replaying previously intercepted user credentials. When the server is configured with a nonce (a single-use security token) lifetime of zero, an attacker can send crafted requests that prematurely clear the client session entry from shared memory, enabling unauthorized access using the replayed credentials.
Меры по смягчению последствий
Ensure that AuthDigestNonceLifetime is not set to 0. If digest authentication is not required, disable mod_auth_digest.
- To retain digest authentication with safe settings, set a positive non-zero value (such as the default 300 seconds) or remove the explicit zero setting from
/etc/httpd/conf/httpd.confor relevant files in/etc/httpd/conf.d/:
- If HTTP digest authentication is not needed, disable the module by commenting out the corresponding line in
/etc/httpd/conf.modules.d/00-base.conf:
- Restart the web server to apply changes:
Warning: Restarting or reloading the httpd service will briefly disrupt active client connections. Disabling the module will break authentication for virtual hosts or directories relying on digest authentication.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | httpd | Affected | ||
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| Red Hat Enterprise Linux 8 | httpd:2.4/httpd | Affected | ||
| Red Hat Enterprise Linux 9 | httpd | Affected | ||
| Red Hat Hardened Images | httpd-main-2.4.69-1.hum1 | Fixed | RHSA-2026:74858 | 02.10.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Authentication bypass by capture-replay in mod_auth_digest in Apache S ...
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
EPSS
8.1 High
CVSS3