CVE-2024-38476

Published Jul 1, 2024

Last updated 6 months ago

Overview

Description
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Source
security@apache.org
NVD status
Modified
Products
http_server, clustered_data_ontap

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@apache.org
CWE-829
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations