cbcvebase.
CVE-2024-38476
published 2024-07-01

CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.0 < 2.4.602.4.60
apache_software_foundationapache_http_server2.4.0 – 2.4.59
applemacos_sequoia
debianapache2< apache2 2.4.61-1~deb12u1 (bookworm)apache2 2.4.61-1~deb12u1 (bookworm)
netappclustered_data_ontap
ubuntuapache2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL