PT-2024-4434 · Apache+10 · Apache Http Server+10

Orange_8361

·

Published

2021-11-09

·

Updated

2026-04-30

·

CVE-2024-38475

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.59 and earlier
Description The vulnerability is caused by improper escaping of output in the mod rewrite module of Apache HTTP Server. This allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally or directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use backreferences or variables as the first segment of the substitution are affected. Some unsafe RewriteRules will be broken by this change, and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained. The vulnerability has been exploited in the wild, with instances of unauthorized access to files and potential session hijacking reported.
Recommendations Apache HTTP Server 2.4.59 and earlier: Update to Apache HTTP Server 2.4.60 or later to fix the vulnerability. As a temporary workaround, consider disabling the mod rewrite module or restricting its use to minimize the risk of exploitation. Restrict access to the mod rewrite module to minimize the risk of exploitation. Avoid using substitutions in server context that use backreferences or variables as the first segment of the substitution until the issue is resolved.

Exploit

Fix

RCE

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

ALSA-2021_4257
ALSA-2022_7647
ALSA-2022_8067
ALSA-2024:4720
ALSA-2024:4726
ALSA-2025_16880
ALT-PU-2024-10005
ALT-PU-2024-10192
ALT-PU-2024-10223
ALT-PU-2024-9738
BDU:2024-04936
BIT-APACHE-2024-38475
CESA-2024_4720
CVE-2024-38475
DSA-5729-1
ELSA-2024-4720
ELSA-2024-4726
ELSA-2024-4943
INFSA-2024_4720
INFSA-2024_4726
MGASA-2024-0258
OESA-2024-1830
OPENSUSE-SU-2024:14116-1
OPENSUSE-SU-2024_2597-1
RHSA-2024:4719
RHSA-2024:4720
RHSA-2024:4726
RHSA-2024:4820
RHSA-2024:4827
RHSA-2024:4830
RHSA-2024:4862
RHSA-2024:4863
RHSA-2024:4938
RHSA-2024:4943
RHSA-2024:5239
RHSA-2024_4720
RHSA-2024_4726
RLSA-2024:4726
RLSA-2024_4720
RLSA-2024_4726
ROSA-SA-2024-2515
SUSE-SU-2024:2436-1
SUSE-SU-2024:2591-1
SUSE-SU-2024:2597-1
SUSE-SU-2024:2624-1
SUSE-SU-2024_2436-1
SUSE-SU-2024_2591-1
SUSE-SU-2024_2597-1
SUSE-SU-2024_2624-1
USN-6885-1
USN-6885-2
USN-6885-3
USN-6885-4
USN-6885-5
USN-6885-6

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu