CVE-2024-38476

Severity
9.8CRITICAL
EPSS
3.5%
top 12.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateApr 15

Description

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

NVDapache/http_server2.4.02.4.60
Alpineapache2< 2.4.60-r0+6
Debianapache2< 2.4.61-1~deb11u1+3

🔴Vulnerability Details

4
CVEList
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect2024-07-01
OSV
CVE-2024-38476: Vulnerability in core of Apache HTTP Server 22024-07-01
GHSA
GHSA-fpq9-w5cw-5hf8: Vulnerability in core of Apache HTTP Server 22024-07-01
OSV
CVE-2024-38476: Vulnerability in core of Apache HTTP Server 22024-07-01

📋Vendor Advisories

8
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core (Apache HTTP Server) — CVE-2024-384762025-04-15
Apple
CVE-2024-38476: macOS Sequoia 15.12024-10-28
Oracle
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) — CVE-2024-384762024-10-15
Ubuntu
Apache HTTP Server vulnerabilities2024-09-18
Ubuntu
Apache HTTP Server vulnerabilities2024-07-08

💬Community

1
HackerOne
important: Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect (CVE-2024-38476)2024-07-13