CVE-2024-38476
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
- Affected products
- Alt Linux, Almalinux, Apache Http Server, Astra Linux, Centos, Check Point Gaia, Linuxmint, Red Hat
- Apache Http Server
- < 2.4.60
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 41.6% (99th percentile)
- Weakness
- CWE-829
- NVD status
- Modified
- Published
- 2024-07-01
CVE-2024-38476 at NVD
1 known exploit for CVE-2024-38476
Proof-of-concept code and exploit modules indexed by Sploitus