The flaw has existed for eight years thanks to a security change in Apache.
Source: Threadpost