CVE-2024-39573
published 2024-07-01CVE-2024-39573: Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be…
PriorityP359high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
35.45%
98.3th percentile
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.60 | 2.4.60 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.59 | — |
| apple | macos_sequoia | — | — |
| debian | apache2 | < apache2 2.4.61-1~deb12u1 (bookworm) | apache2 2.4.61-1~deb12u1 (bookworm) |
| netapp | ontap | — | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_redhat8.1HIGH
vendor_apache7.5
vendor_debian7.5HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-05-29·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-8338-1 introduced a regression in Apache HTTP Server
USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression that prevented mod_http2 from loading on Ubuntu
18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause Apache
HTTP Server to consume resources, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802)
Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly
handled certain response headers.
Apple
CVE-2024-39573: macOS Sequoia 15.1
vendor_apple·2024-10-28·CVSS 7.5
CVE-2024-39573 [HIGH] CVE-2024-39573: macOS Sequoia 15.1
Apple Security Update: About the security content of macOS Sequoia 15.1
Product: macOS Sequoia
Version: 15.1
CVE: CVE-2024-39573
Component: CVE-2024-39573
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2024-07-11·CVSS 5.4
[MEDIUM] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-6885-1 introduced a regression in Apache HTTP Server.
USN-6885-1 fixed vulnerabilities in Apache HTTP Server. One of the security
fixes introduced a regression when proxying requests to a HTTP/2 server.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-07-08·CVSS 5.4
CVE-2024-38475 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could possibly
use this issue to execute scripts in directori
Red Hat
httpd: Encoding problem in mod_proxy
vendor_redhat·2024-07-01·CVSS 8.1
CVE-2024-38473 [HIGH] CWE-116 httpd: Encoding problem in mod_proxy
httpd: Encoding problem in mod_proxy
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
A flaw was found in the mod_proxy module of httpd. Due to an encoding problem, specially crafted request URLs with incorrect encoding can be sent to backend services, potentially bypassing authentication.
Statement: This issue affects configurations where mechanisms other than ProxyPass/ProxyPassMatch or RewriteRule with the 'P' flag are used to configure a request to be proxied, such as SetHandler or inadvertent proxying via CVE-2024-39573. Note that these alternate mechan
Red Hat
httpd: Potential SSRF in mod_rewrite
vendor_redhat·2024-07-01·CVSS 7.5
CVE-2024-39573 [HIGH] CWE-20 httpd: Potential SSRF in mod_rewrite
httpd: Potential SSRF in mod_rewrite
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
A flaw was found in the mod_rewrite module of httpd. A potential SSRF allows an attacker to cause unsafe rules used in the RewriteRule directive to unexpectedly set up URLs to be handled by the mod_proxy module.
Statement: This issue only affects configurations with unsafe rules used in the RewriteRule directive.
Additionally, this flaw requires mod_rewrite and mod_proxy to be loaded and being used. These modules can be disabled via the configuration file if their functionality are not needed.
Red Hat En
Debian
CVE-2024-39573: apache2 - Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an...
vendor_debian·2024·CVSS 7.5
CVE-2024-39573 [HIGH] CVE-2024-39573: apache2 - Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an...
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 2.4.61-1~deb12u1)
bullseye: resolved (fixed in 2.4.61-1~deb11u1)
forky: resolved (fixed in 2.4.60-1)
sid: resolved (fixed in 2.4.60-1)
trixie: resolved (fixed in 2.4.60-1)
Apache
Apache httpd: CVE-2024-39573
vendor_apache·CVSS 7.5
CVE-2024-39573 Apache httpd: CVE-2024-39573
Apache httpd: CVE-2024-39573
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Acknowledgements: finder: Orange Tsai (@orange_8361) from DEVCORE Reported to security team 2024-04-01 Update 2.4.60 released 2024-07-01 Affects 2.4.0 through 2.4.59
Severity: moderate
Affected versions: 2.4.60,
OSV
apache2 regression
osv·2024-07-11·CVSS 5.4
[MEDIUM] apache2 regression
apache2 regression
USN-6885-1 fixed vulnerabilities in Apache HTTP Server. One of the security
fixes introduced a regression when proxying requests to a HTTP/2 server.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apach
OSV
apache2 vulnerabilities
osv·2024-07-08·CVSS 5.4
CVE-2024-36387 [MEDIUM] apache2 vulnerabilities
apache2 vulnerabilities
Marc Stern discovered that the Apache HTTP Server incorrectly handled
serving WebSocket protocol upgrades over HTTP/2 connections. A remote
attacker could possibly use this issue to cause the server to crash,
resulting in a denial of service. (CVE-2024-36387)
Orange Tsai discovered that the Apache HTTP Server mod_proxy module
incorrectly sent certain request URLs with incorrect encodings to backends.
A remote attacker could possibly use this issue to bypass authentication.
(CVE-2024-38473)
Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could possibly
use this issue to execute scripts in directories not directly reachable
by any URL, or cause a denial of service. Some environments
GHSA
GHSA-2wcw-rcf9-qm36: Potential SSRF in mod_rewrite in Apache HTTP Server 2
ghsa_unreviewed·2024-07-01
CVE-2024-39573 [HIGH] CWE-20 GHSA-2wcw-rcf9-qm36: Potential SSRF in mod_rewrite in Apache HTTP Server 2
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
OSV
CVE-2024-39573: Potential SSRF in mod_rewrite in Apache HTTP Server 2
osv·2024-07-01·CVSS 7.5
CVE-2024-39573 [HIGH] CVE-2024-39573: Potential SSRF in mod_rewrite in Apache HTTP Server 2
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
OSV
CVE-2024-39573: Potential SSRF in mod_rewrite in Apache HTTP Server 2
osv·2024-07-01·CVSS 7.5
CVE-2024-39573 [HIGH] CVE-2024-39573: Potential SSRF in mod_rewrite in Apache HTTP Server 2
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
No detection rules found.
No public exploits indexed.
HackerOne
moderate: Apache HTTP Server: mod_rewrite proxy handler substitution (CVE-2024-39573) CWE-20 Improper Input Validation
hackerone·2024-08-12·CVSS 8.1
CVE-2024-39573 [HIGH] moderate: Apache HTTP Server: mod_rewrite proxy handler substitution (CVE-2024-39573) CWE-20 Improper Input Validation
moderate: Apache HTTP Server: mod_rewrite proxy handler substitution (CVE-2024-39573) CWE-20 Improper Input Validation
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
###moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473)
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier a
HackerOne
moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473)
hackerone·2024-07-13·CVSS 8.1
CVE-2024-38473 [HIGH] moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473)
moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473)
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
###moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473)
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs
https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://security.netapp.com/advisory/ntap-20240712-0001/http://seclists.org/fulldisclosure/2024/Oct/11http://www.openwall.com/lists/oss-security/2024/07/01/11https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://security.netapp.com/advisory/ntap-20240712-0001/
2024-07-01
Published