PT-2024-5104 · Apache+10 · Apache Http Server+10
Orange Tsai
+1
·
Published
2024-04-01
·
Updated
2026-05-28
·
CVE-2024-39573
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache HTTP Server versions 2.4.59 and earlier
Description:
The issue is related to a potential Server-Side Request Forgery (SSRF) in the mod rewrite module of the Apache HTTP Server. This allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod proxy. The vulnerability is due to insufficient validation of incoming requests.
Recommendations:
For Apache HTTP Server versions 2.4.59 and earlier, upgrade to version 2.4.60, which fixes this issue.
Fix
SSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu