PT-2024-5185 · Apache+6 · Apache Http Server+6
Published
2024-07-09
·
Updated
2026-03-07
·
CVE-2024-40725
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apache HTTP Server versions 2.4.61
Description:
The issue is related to the core of Apache HTTP Server, where a partial fix ignores some use of the legacy content-type based configuration of handlers. This can result in source code disclosure of local content under certain circumstances, such as when files are requested indirectly. For example, PHP scripts may be served instead of interpreted.
Recommendations:
Upgrade to version 2.4.62, which fixes this issue.
Exploit
Fix
Improper Access Control
SSRF
Incorrect Privilege Assignment
Information Disclosure
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu