PT-2024-5185 · Apache+6 · Apache Http Server+6

CVE-2024-40725

·

Published

2024-07-09

·

Updated

2026-06-29

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions 2.4.61
Description: The issue is related to the core of Apache HTTP Server, where a partial fix ignores some use of the legacy content-type based configuration of handlers. This can result in source code disclosure of local content under certain circumstances, such as when files are requested indirectly. For example, PHP scripts may be served instead of interpreted.
Recommendations: Upgrade to version 2.4.62, which fixes this issue.

Exploit

Fix

Exposure of Resource to Wrong Sphere

SSRF

Incorrect Privilege Assignment

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2024-11994
ALT-PU-2024-11996
AZL-43414
AZL-43427
BDU:2024-05368
BDU:2024-05741
BIT-APACHE-2024-40725
CVE-2024-40725
MGASA-2024-0272
OESA-2024-2288
OPENSUSE-SU-2024:14245-1
OPENSUSE-SU-2024_3742-1
OPENSUSE-SU-2024_3864-1
SUSE-SU-2024:3742-1
SUSE-SU-2024:3750-1
SUSE-SU-2024:3864-1
SUSE-SU-2024_3742-1
SUSE-SU-2024_3750-1
SUSE-SU-2024_3864-1
SUSE-SU-2025:02241-1
SUSE-SU-2025_02241-1
SUSE-SU-2026:2686-1
USN-6902-1

Affected Products

Alt Linux
Apache Http Server
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu