Description
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Questions and Answers Security Bypass (1.1.9)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-1501)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-5084)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1099)