REDHAT-BUG-2465293: Medium severity Apache HTTP Server vulnerability
A timing attack against modauthdigest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Server mod_auth_digestto a version that resolves this vulnerability.Fixed in 2.4.67
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2465293?
The severity of REDHAT-BUG-2465293 is rated as medium with a score of 4.
What is the nature of the vulnerability REDHAT-BUG-2465293?
REDHAT-BUG-2465293 is a timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 that allows a bypass of Digest authentication.
How do I fix REDHAT-BUG-2465293?
To fix REDHAT-BUG-2465293, users are recommended to upgrade to Apache HTTP Server version 2.4.67.
Who is affected by REDHAT-BUG-2465293?
Users of Apache HTTP Server version 2.4.66 are affected by REDHAT-BUG-2465293.
When was REDHAT-BUG-2465293 published?
REDHAT-BUG-2465293 was published on May 4, 2026.