CVE-2024-38474
published 2024-07-01CVE-2024-38474: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.46%
82.6th percentile
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.60 | 2.4.60 |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.59 | — |
| debian | apache2 | < apache2 2.4.61-1~deb12u1 (bookworm) | apache2 2.4.61-1~deb12u1 (bookworm) |
| netapp | clustered_data_ontap | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
apache2 regression
osv·2025-08-13·CVSS 9.8
CVE-2024-38474 [CRITICAL] apache2 regression
apache2 regression
USN-6885-1 fixed vulnerabilities in Apache. The patch for
CVE-2024-38474 was incomplete and caused a regression.
This update provides the fix for this issue.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite
module incorrectly handled certain substitutions. A remote attacker
could possibly use this issue to execute scripts in directories
not directly reachable by any URL, or cause a denial of service.
Some environments may require using the new UnsafeAllow3F flag
to handle unsafe substitutions. (CVE-2024-38474)
OSV
apache2 vulnerabilities
osv·2025-07-21·CVSS 9.8
[CRITICAL] apache2 vulnerabilities
apache2 vulnerabilities
USN-6885-1 fixed vulnerabilities in Apache. This update provides
the corresponding updates for Ubuntu 14.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474, CVE-2024-38475)
OSV
apache2 regression
osv·2025-04-07·CVSS 9.8
CVE-2024-38474 [CRITICAL] apache2 regression
apache2 regression
USN-6885-1 fixed a vulnerability in Apache. The patch
for CVE-2024-38474 was incomplete and caused regressions.
This update provides the fix for that issue.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474)
OSV
apache2 vulnerabilities
osv·2024-09-18·CVSS 9.8
[CRITICAL] apache2 vulnerabilities
apache2 vulnerabilities
USN-6885-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474, CVE-2024-38475)
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
certain response headers. A remote attacker could possibly use this issue
to obtain sensitive information, execute local scripts, or perform SSRF
OSV
apache2 regression
osv·2024-07-11·CVSS 5.4
[MEDIUM] apache2 regression
apache2 regression
USN-6885-1 fixed vulnerabilities in Apache HTTP Server. One of the security
fixes introduced a regression when proxying requests to a HTTP/2 server.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apach
OSV
apache2 vulnerabilities
osv·2024-07-08·CVSS 5.4
CVE-2024-36387 [MEDIUM] apache2 vulnerabilities
apache2 vulnerabilities
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could possibly
use this issue to execute scripts in directories not directly reachable
by any URL, or cause a denial of service. Some environments
OSV
CVE-2024-38474: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2
osv·2024-07-01·CVSS 9.8
CVE-2024-38474 [CRITICAL] CVE-2024-38474: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
OSV
CVE-2024-38474: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2
osv·2024-07-01·CVSS 9.8
CVE-2024-38474 [CRITICAL] CVE-2024-38474: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
GHSA
GHSA-x6g9-g4wf-qrf7: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2
ghsa_unreviewed·2024-07-01
CVE-2024-38474 [CRITICAL] CWE-116 GHSA-x6g9-g4wf-qrf7: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2025-08-13·CVSS 9.8
CVE-2024-38474 [CRITICAL] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-6885-1 introduced a regression in Apache HTTP Server.
USN-6885-1 fixed vulnerabilities in Apache. The patch for
CVE-2024-38474 was incomplete and caused a regression.
This update provides the fix for this issue.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite
module incorrectly handled certain substitutions. A remote attacker
could possibly use this issue to execute scripts in directories
not directly reachable by any URL, or cause a denial of service.
Some environments may require using the new UnsafeAllow3F flag
to handle unsafe substitutions. (CVE-2024-38474)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2025-07-21·CVSS 9.8
CVE-2024-38474 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-6885-1 fixed vulnerabilities in Apache. This update provides
the corresponding updates for Ubuntu 14.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474, CVE-2024-38475)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2025-04-07·CVSS 9.8
CVE-2024-38474 [CRITICAL] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-6885-1 introduced a regression in Apache HTTP Server.
USN-6885-1 fixed a vulnerability in Apache. The patch
for CVE-2024-38474 was incomplete and caused regressions.
This update provides the fix for that issue.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-09-18·CVSS 9.8
CVE-2024-38475 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-6885-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474, CVE-2024-38475)
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
certain response headers. A remote attacker could possibly
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2024-07-11·CVSS 5.4
[MEDIUM] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-6885-1 introduced a regression in Apache HTTP Server.
USN-6885-1 fixed vulnerabilities in Apache HTTP Server. One of the security
fixes introduced a regression when proxying requests to a HTTP/2 server.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-07-08·CVSS 5.4
CVE-2024-38475 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could possibly
use this issue to execute scripts in directori
Red Hat
httpd: Substitution encoding issue in mod_rewrite
vendor_redhat·2024-07-01·CVSS 9.8
CVE-2024-38474 [CRITICAL] CWE-116 httpd: Substitution encoding issue in mod_rewrite
httpd: Substitution encoding issue in mod_rewrite
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
A flaw was found in the mod_rewrite module of httpd. Due to a substitution encoding issue, specially crafted requests may allow an attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant
Debian
CVE-2024-38474: apache2 - Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earl...
vendor_debian·2024·CVSS 9.8
CVE-2024-38474 [CRITICAL] CVE-2024-38474: apache2 - Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earl...
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
Scope: local
bookworm: resolved (fixed in 2.4.61-1~deb12u1)
bullseye: resolved (fixed in 2.4.61-1~deb11u1)
forky: resolved (fixed in 2.4.60-1)
sid: resolved (fixed in 2.4.60-1)
trixie: resolved (fixed in 2.4.60-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-31651 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
bugzilla·2025-04-28·CVSS 9.8
CVE-2025-31651 [CRITICAL] CVE-2025-31651 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
CVE-2025-31651 tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Discussion:
see apache httpd CVE-2024-38474, this issue is not identical
---
This issue has been addressed in the following products:
Red Hat JBoss Web Server 6.1.3
Via RHSA-2025:
HackerOne
important: Apache HTTP Server weakness with encoded question marks in backreferences (CVE-2024-38474)
hackerone·2024-07-13·CVSS 9.8
CVE-2024-38474 [CRITICAL] important: Apache HTTP Server weakness with encoded question marks in backreferences (CVE-2024-38474)
important: Apache HTTP Server weakness with encoded question marks in backreferences (CVE-2024-38474)
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Some RewriteRules that capture and substitute unsafely will now
arXiv
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
arxiv_fulltext·2025-06-30·CVSS 9.8
[CRITICAL] Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
titlepage
*1cm
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure \ 1cm]
Alessio Di Santo ([email protected])
Università degli Studi dell’Aquila, L’Aquila, Abruzzo, Italy
Date: July 1,2025
!60 "Non videmus ea quae mox futura sunt" \ 0.5cm]
!60(We do not see the things that will soon be) — Marcus Tullius Cicero
titlepage
## Executive Summary
This analysis focuses on a single Azure-hosted Virtual Machine at 52.230.23[.]114 that the adversary converted into an all-in-one delivery, staging and Command-and-Control node. The host advertises an out-of-date Apache 2.4.52 instance whose open directory exposes phishing lures, PowerShell loaders, Reflective Shell-Code, compiled Havoc Demon implants and a toolbox of lateral-movement binaries; the same server als
2024-07-01
Published