CVE-2024-40725
published 2024-07-18CVE-2024-40725: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
4.13%
89.7th percentile
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.62, which fixes this issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| debian | apache2 | < apache2 2.4.62-1~deb12u1 (bookworm) | apache2 2.4.62-1~deb12u1 (bookworm) |
| msrc | azl3_httpd_2.4.61-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_httpd_2.4.62-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_httpd_2.4.59-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_httpd_2.4.62-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-40725: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2
osv·2024-07-18·CVSS 6.2
CVE-2024-40725 [MEDIUM] CVE-2024-40725: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.
GHSA
GHSA-x749-289q-pg9q: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2
ghsa_unreviewed·2024-07-18·CVSS 6.2
CVE-2024-40725 [MEDIUM] CWE-668 GHSA-x749-289q-pg9q: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.62, which fixes this issue.
OSV
CVE-2024-40725: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2
osv·2024-07-18·CVSS 6.2
CVE-2024-40725 [MEDIUM] CVE-2024-40725: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.62, which fixes this issue.
Red Hat
httpd: source code disclosure with handlers configured via AddType
vendor_redhat·2024-07-18·CVSS 6.2
CVE-2024-40725 [MEDIUM] CWE-668 httpd: source code disclosure with handlers configured via AddType
httpd: source code disclosure with handlers configured via AddType
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.62, which fixes this issue.
A flaw was found in httpd. The fix for CVE-2024-39884 ignores some uses of the legacy content-type based configuration of handlers. "AddType" and similar configurations, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For ex
Ubuntu
Apache HTTP Server vulnerability
vendor_ubuntu·2024-07-18
CVE-2024-40725 Apache HTTP Server vulnerability
Title: Apache HTTP Server vulnerability
Summary: Apache HTTP Server could be made to expose sensitive information over the
network.
It was discovered that the Apache HTTP Server incorrectly handled certain
handlers configured via AddType. A remote attacker could possibly use this
issue to obtain source code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Apache HTTP Server: source code disclosure with handlers configured via AddType
vendor_msrc·2024-07-09·CVSS 5.3
CVE-2024-40725 [MEDIUM] CWE-668 Apache HTTP Server: source code disclosure with handlers configured via AddType
Apache HTTP Server: source code disclosure with handlers configured via AddType
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Debian
CVE-2024-40725: apache2 - A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignor...
vendor_debian·2024·CVSS 6.2
CVE-2024-40725 [MEDIUM] CVE-2024-40725: apache2 - A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignor...
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 2.4.62-1~deb12u1)
bullseye: resolved (fixed in 2.4.62-1~deb11u1)
forky: resolved (fixed in 2.4.62-1)
sid: resolved (fixed in 2.4.62-1)
trixie: resolved (fixed in 2.4.62-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-18
Published