PT-2024-6069 · Apache+10 · Apache Http Server+10
Orange_8361
·
Published
2024-04-01
·
Updated
2026-05-28
·
CVE-2024-38473
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.59 and earlier
Description
The issue is related to an encoding problem in the mod proxy component of the Apache HTTP Server, which can allow an attacker to send request URLs with incorrect encoding to backend services, potentially bypassing authentication via crafted requests. This could enable a remote attacker to access confidential data and cause a denial of service.
Recommendations
For Apache HTTP Server versions 2.4.59 and earlier, upgrade to version 2.4.60, which fixes this issue.
Exploit
Fix
DoS
SSRF
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu