Severity
6.2MEDIUM
EPSS
0.2%
top 52.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 4
Latest updateJul 18

Description

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.61, which fixes this issue.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages4 packages

CVEListV5apache_software_foundation/apache_http_server2.4.602.4.61+1
NVDapache/http_server2.4.60
Alpineapache2< 2.4.61-r0+6
Debianapache2< 2.4.61-1+2

Also affects: Ontap Tools 10

🔴Vulnerability Details

4
CVEList
Apache HTTP Server: source code disclosure with handlers configured via AddType2024-07-04
OSV
CVE-2024-39884: A regression in the core of Apache HTTP Server 22024-07-04
GHSA
GHSA-5r34-776f-3434: A regression in the core of Apache HTTP Server 22024-07-04
OSV
CVE-2024-39884: A regression in the core of Apache HTTP Server 22024-07-04

📋Vendor Advisories

6
Red Hat
httpd: source code disclosure with handlers configured via AddType2024-07-18
Microsoft
Apache HTTP Server: source code disclosure with handlers configured via AddType2024-07-09
Ubuntu
Apache HTTP Server vulnerabilities2024-07-08
Red Hat
httpd: source code disclosure with handlers configured via AddType2024-07-04
Debian
CVE-2024-39884: apache2 - A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the le...2024