cbcvebase.
CVE-2024-38476
published 2024-07-01

CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
41.61%
98.5th percentile
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.0 < 2.4.602.4.60
apache_software_foundationapache_http_server2.4.0 – 2.4.59
applemacos_sequoia
debianapache2< apache2 2.4.61-1~deb12u1 (bookworm)apache2 2.4.61-1~deb12u1 (bookworm)
netappclustered_data_ontap
ubuntuapache2

Detection & IOCsextracted from sources · hover to see the quote

  • Target versions: Apache HTTP Server 2.4.59 and earlier are vulnerable; the attack vector is malicious or exploitable response headers from backend applications, enabling information disclosure, SSRF, or local script execution.
  • The vulnerability is exploitable remotely over HTTP; detection should focus on anomalous or crafted response headers returned by backend/proxy applications to the Apache HTTP Server core.
  • Monitor for SSRF-indicative outbound requests originating from the Apache HTTP Server process, which may indicate exploitation via a malicious backend response header.
  • This flaw can only be triggered through backend applications; detection should include inspection of proxy/backend response headers for unexpected or injected header values that could influence Apache core behavior.
  • ·Red Hat Enterprise Linux 6 is not affected because the vulnerable code was introduced in a newer version of httpd; do not prioritize patching on RHEL 6 systems.
  • ·The fix for CVE-2024-38476 (introduced in Apache HTTP Server 2.4.60) itself caused a regression (CVE-2024-39884) that can lead to source code disclosure via legacy AddType/content-type handler configuration; upgrading to 2.4.61 is required to fully remediate both issues.
  • ·No practical mitigation short of patching has been identified by Red Hat; update the affected package as soon as possible.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.