PT-2024-4623 · Apache+10 · Apache Http Server+10

Orange_8361

·

Published

2024-07-01

·

Updated

2026-05-28

·

CVE-2024-38476

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions 2.4.59 and earlier
Description: The issue is related to the core of the Apache HTTP Server, where malicious or exploitable response headers from backend applications can lead to information disclosure, Server-Side Request Forgery (SSRF), or local script execution. This can be exploited by an attacker to execute arbitrary code through internal redirection. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: To resolve the issue, users are recommended to upgrade to version 2.4.60, which fixes this issue. As a temporary workaround, consider restricting access to backend applications whose response headers are malicious or exploitable until the upgrade is applied. Avoid using the vulnerable core functionality of the Apache HTTP Server until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

ALSA-2024:5138
ALSA-2024:5193
ALT-PU-2024-10005
ALT-PU-2024-10192
ALT-PU-2024-10223
ALT-PU-2024-9738
BDU:2024-05131
BIT-APACHE-2024-38476
CESA-2024_5193
CVE-2024-38476
DSA-5729-1
INFSA-2024_5138
INFSA-2024_5193
MGASA-2024-0258
OESA-2024-2101
OPENSUSE-SU-2024:14116-1
OPENSUSE-SU-2024_2597-1
RHSA-2024:5138
RHSA-2024:5193
RHSA-2024:5239
RHSA-2024:5812
RHSA-2024:5832
RHSA-2024:6136
RHSA-2024:6467
RHSA-2024:6468
RHSA-2024:6583
RHSA-2024:6584
RHSA-2024:7101
RHSA-2024_5138
RHSA-2024_5193
RLSA-2024:5138
RLSA-2024:5193
ROSA-SA-2024-2515
SUSE-SU-2024:2560-1
SUSE-SU-2024:2591-1
SUSE-SU-2024:2597-1
SUSE-SU-2024:2624-1
SUSE-SU-2024_2560-1
USN-6885-1
USN-6885-2
USN-6885-3
USN-6885-4
USN-6885-6
USN-8338-1

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu