PT-2024-4434 · Apache+10 · Apache Http Server+10
Orange_8361
·
Published
2021-11-09
·
Updated
2026-04-30
·
CVE-2024-38475
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.59 and earlier
Description
The vulnerability is caused by improper escaping of output in the mod rewrite module of Apache HTTP Server. This allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally or directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use backreferences or variables as the first segment of the substitution are affected. Some unsafe RewriteRules will be broken by this change, and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained. The vulnerability has been exploited in the wild, with instances of unauthorized access to files and potential session hijacking reported.
Recommendations
Apache HTTP Server 2.4.59 and earlier: Update to Apache HTTP Server 2.4.60 or later to fix the vulnerability.
As a temporary workaround, consider disabling the mod rewrite module or restricting its use to minimize the risk of exploitation.
Restrict access to the mod rewrite module to minimize the risk of exploitation.
Avoid using substitutions in server context that use backreferences or variables as the first segment of the substitution until the issue is resolved.
Exploit
Fix
RCE
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu