CVE-2024-38473

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*

History

01 Jul 2025, 20:25

Type Values Removed Values Added
CPE cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
First Time Netapp
Netapp ontap
Apache http Server
Apache
CWE CWE-116
References
  • () http://www.openwall.com/lists/oss-security/2024/07/01/6 - Mailing List
References () https://security.netapp.com/advisory/ntap-20240712-0001/ - () https://security.netapp.com/advisory/ntap-20240712-0001/ - Third Party Advisory
References () https://httpd.apache.org/security/vulnerabilities_24.html - () https://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory

12 Jul 2024, 14:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240712-0001/ -

01 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-01 19:15

Updated : 2025-07-01 20:25


NVD link : CVE-2024-38473

Mitre link : CVE-2024-38473


JSON object : View

Products Affected

apache

  • http_server

netapp

  • ontap
CWE

No CWE.