The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.