The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.
No PoCs from references.
- https://github.com/kwburns/CVE
- https://github.com/packetlabs/vulnerability-advisory